Third Party Index

Snapshot 67142

Document
Privacy policy
URL
https://malbek.klix.pro/klix/tpl?cid=3716469906141612134&mode=1
Fetched
HTTP status
200
Content type
text/html
Fetch mode
browser
Size
279829 bytes
SHA-256 (raw)
4d4b2d34f540a3097a95102f6e06dd2f69f0ff173a7949121dec45c479195d7e
SHA-256 (normalized text)
775f8b3ec1671bcc24c15a5b80e165b9940287f86d6373ac5086f02d5260b6dd

Normalized text

Scripts and page chrome removed; this is what change detection compares.

MALBEC SOLUTIONS, INC. D/B/A MALBEK
Privacy Policy
Effective date: September 3, 2026 Last updated: September 3, 2026
1. About this policy
1.1 Who we are
Malbec Solutions, Inc. d/b/a Malbek ("Malbek", "we", "us" or "our") operates the malbek.io website (the
"Site") and a contract lifecycle management platform consisting of Malbek CLM, Malbek AI, Malbek
BusinessIQ, Malbek Klix and Malbek Marketplace (together, the "Service"). Our headquarters is at 300
Carnegie Center Drive, Suite 210, Princeton, New Jersey 08540, United States.
This policy explains what we do with personal information. It applies to the Site, the Service, our
marketing and events, our support channels and our recruiting.
1.2 We act in two different roles, and the difference matters
Most of the confusion in privacy notices for business software comes from mixing two roles together. We
have separated them.
– As a controller. When you visit the Site, ask for a demo, register for a webinar, contact support,
apply for a job or otherwise deal with Malbek directly, we decide what information to collect and why.
Part One covers that. In California we are a business; in Canada we are the organization responsible
for that information.
– As a processor. When our customers load their contracts, their counterparties’ details and their own
people’s details into the Service, they decide what to collect and why, and we handle it on their
instructions. Part Two covers that. In California we are a service provider; in Canada the customer
remains accountable and we act on its behalf.
If you are an employee of one of our customers and you want to know why your details appear in a
contract record, the customer, not Malbek, is the right place to start. Section 3.4 explains what we do with
requests that reach us anyway.
1.3 Definitions
– Personal information means information that identifies, relates to, describes or could reasonably be
linked with an identified or identifiable individual. We use it to mean the same thing as "personal
data" under European and Canadian law. Where a statute defines a term more narrowly, the
statutory definition applies in the section dealing with that statute.
– Customer data means the contract documents, contract metadata, user account records and related
content that a customer or its authorized users load into or generate within the Service.
– Sensitive personal information has the meaning given to it in the applicable privacy statute, and
includes government identifiers, precise geolocation, account log-in credentials, financial account
details, and information about health, racial or ethnic origin, religion, sex life or sexual orientation and
union membership.
– Customer means an organization that has entered into a subscription agreement with Malbek for the
Service.
1.4 Other documents
This policy sits alongside the following, which control where they conflict with it:
– Data Processing Addendum. Available through the Malbek Trust Center at trust.malbek.io. It
governs customer data and includes our standard contractual clauses, security measures and breach
obligations.
– Subprocessor list. Published at trust.malbek.io/subprocessors and kept current.
– Terms of Use. At malbek.io/terms-of-service, together with any master subscription agreement
between Malbek and a customer.
– Trust Center. At trust.malbek.io, for our security attestations, audit reports, penetration testing
summary, architecture documentation and control descriptions.
Using the Service does not by itself constitute consent to this policy. Where we rely on consent, we ask
for it separately and you can withdraw it.
2. Part One: information we collect for our own purposes
This part applies when Malbek decides what to collect and why. It covers visitors to the Site, people who
contact us or ask about the Service, attendees at our events and webinars, partner and vendor contacts,
the administrators and named users at our customers insofar as we manage the commercial relationship
with them, and job applicants.
2.1 What we collect and why
Category and examples Where it comes
from
Why we use it Legal basis in the
EEA, UK and
Switzerland
Identifiers and business
contact details: name, job title,
employer, business email,
business phone, country.
From you, through
forms, email,
events and demo
requests. From
partners and
referral sources.
From business
contact and intent
data providers.
To respond to enquiries, run
demos and trials, administer
accounts and provide support.
Performance of a
contract, or steps taken
at your request before
entering into one.
Legitimate interests in
operating a business-to-
business relationship.
Account and profile data for
named users of the Service:
username, role, permissions,
authentication events,
preferences.
From you and from
your organization’s
administrator.
To provision and secure
accounts, apply permissions
and provide support.
Performance of a
contract with your
organization, and our
legitimate interest in
securing the Service.
Marketing and engagement
data: campaign responses,
webinar and event attendance,
content downloads, email
opens and clicks, and intent
and firmographic data.
From you. From
our marketing
automation
platform. From
event organizers
where you agreed
to the exchange.
From intent data
providers.
To send marketing about the
Service, measure campaign
performance and prioritize
outreach.
Consent where local law
requires it. Otherwise
legitimate interests in
direct marketing to
business contacts. You
can object at any time.
Technical and usage data: IP
address, device and browser
type, operating system,
internet service provider,
referring and exit pages, date
and time stamps, clickstream,
pages viewed, and cookie and
similar identifiers.
Automatically, from
your device when
you use the Site or
the Service.
To operate and secure the
Site and Service, diagnose
faults, measure performance
and understand which content
is useful.
Legitimate interests in
operating, securing and
improving our own
systems. Consent for
non-essential cookies
and similar
technologies.
Support and communications
data: tickets, correspondence,
and call or meeting notes.
From you. To resolve issues, maintain a
service record and train our
support team.
Performance of a
contract and legitimate
interests in providing
effective support.
Category and examples Where it comes
from
Why we use it Legal basis in the
EEA, UK and
Switzerland
Survey, sweepstake and
contest data: responses, and
the name, email and mailing
address needed to administer
an entry or send a prize.
From you,
voluntarily.
To run the activity, contact
winners and improve the
Service.
Consent. Participation is
always optional.
Recruiting data: application,
CV or resume, work history,
references and interview
notes.
From you, from
recruiters, and
from public
professional
profiles where you
have made them
available.
To assess your application
and, where you agree, to
consider you for later roles.
Steps taken at your
request before entering
into a contract, and
legitimate interests in
running a recruitment
process.
Billing and transaction data:
purchase orders, invoices and
billing contact details.
From the
customer.
To invoice, collect payment
and meet tax and accounting
obligations.
Performance of a
contract and compliance
with a legal obligation.
We do not seek sensitive personal information from you in our own right, and we ask you not to send it to
us. If you volunteer it, for example in a support ticket or a job application, we use it only for the purpose
you gave it to us for.
2.2 Who we disclose it to
We disclose personal information to the following categories of recipients. Our subprocessors are named,
with their location and function, at trust.malbek.io/subprocessors, which is the authoritative and current
list.
– Cloud hosting and infrastructure providers, including Amazon Web Services and Cloudflare.
– Customer relationship and marketing platforms, including Salesforce, HubSpot and Outreach.
– Intent data and analytics providers, including 6sense and Google Analytics.
– Support, ticketing, training and collaboration providers, including Zendesk, Planhat, Smartsheet
and LearnUpon.
– Survey providers, including SurveyMonkey.
– Artificial intelligence providers, on the terms described in Section 4.
– Payment, billing and collections providers.
– Professional advisers, including lawyers, auditors, insurers and accountants.
– Government authorities, on the terms in Section 12.
We do not disclose personal information to credit reference agencies, data brokers, information resellers
or advertising platforms, and we do not disclose it to anyone for their own independent marketing.
2.3 Advertising, analytics and opt-out preference signals
We do not sell personal information. We do not share it for cross-context behavioral advertising, and we
do not process it for targeted advertising, as those terms are defined in United States state privacy law.
We use analytics only to understand how our own Site and Service are used.
We honor opt-out preference signals, including the Global Privacy Control. When your browser or
extension sends the Sec-GPC signal, we treat it as an instruction to opt out of any sale or sharing of
personal information and of processing for targeted advertising, and we apply it without asking you to
create an account or take any further step. Because the signal is tied to a browser, it does not carry
across to a different browser or device.
We do not respond to Do Not Track browser signals, because no common standard for them has been
agreed. The Global Privacy Control is the mechanism we support.
2.4 Marketing communications and consent
We send marketing about the Service to business contacts. Every marketing email carries an unsubscribe
link that works for at least 60 days after the message is sent, and we act on unsubscribe requests within
10 business days. Every message identifies Malbek and gives a mailing address. You can also write to
privacy@malbek.io.
In Canada, we send commercial electronic messages only where we have express consent or where
consent is implied under Canada’s Anti-Spam Legislation, for example because of an existing business
relationship. We keep records of the consent we rely on.
Where we rely on consent, you can withdraw it at any time. Withdrawing consent does not affect the
lawfulness of anything we did before you withdrew it, and it does not affect processing we carry out on
another basis.
Unsubscribing from marketing does not stop service messages about your account, security, billing or
changes to our terms.
2.5 Cookies and similar technologies
Cookies are small files placed on your device. We also use pixels, tags, local storage and similar
technologies. Annex C describes the categories we use and what they do.
Strictly necessary cookies are set whenever you use the Site, because the Site cannot work without
them. In the European Economic Area, the United Kingdom and Switzerland, and anywhere else local law
requires it, every other category is set only after you consent through our cookie banner. You can change
or withdraw your choice at any time through the cookie preferences control on the Site.
Elsewhere you can manage cookies through the banner or through your browser settings. Turning
cookies off may stop parts of the Site or Service from working.
The cookie preferences control lists the exact name, provider and lifespan of every cookie in use and is
kept current automatically.
2.6 Job applicants
We use recruiting information to assess applications, to communicate with you about a role and to meet
our obligations as an employer. We keep unsuccessful applications for as long as we need them to
consider you for later roles and to respond to any related claim, unless you ask us to delete them sooner.
California applicants have the same rights under state law as any other California resident, and Section 9
applies to them.
3. Part Two: customer data we process on a customer’s instructions
3.1 What we receive and on what terms
When a customer uses the Service, we receive whatever that customer chooses to put into it. In practice
this includes email addresses, usernames, first and last names, job titles, company information, and the
contents of contracts and the metadata drawn from them. Contracts can contain personal information
about employees, signatories and counterparty contacts, and occasionally sensitive categories such as
government identifiers or financial account details.
What is collected is the customer’s decision, not ours. We process it only on the customer’s documented
instructions, as set out in the Data Processing Addendum and the customer’s subscription agreement.
For these purposes the customer is the controller under the GDPR, the business under California law and
the accountable organization under Canadian law.
We do not use customer data for our own purposes. We do not sell it, share it for advertising, or disclose
it to data brokers, information resellers, credit reference agencies or advertising platforms, and we will not
do so at any time.
3.2 Approved integrations
The Service integrates with third-party software such as Salesforce, Microsoft Word and others your
organization enables through Malbek Marketplace. Before an integration exchanges information, we ask
for the specific consent required to connect the accounts, and the information exchanged is limited to
what the integration needs, which your organization configures. It typically includes a first and last name,
a username and an email address.
No Malbek employee reads the contents of an integration exchange unless we need to investigate a
technical fault or we suspect misuse of the Service. Where that happens, access is limited to the
personnel who need it, it is logged, and any analysis we retain afterwards is aggregated and used only for
internal business purposes, in accordance with applicable privacy law.
3.3 Contract records, permissions and audit
Contract records held in the Service, meaning the documents and the associated data whether together
or separately, can be restricted from viewing or use after signature. The customer administrator controls
those settings. Changes to security configuration, including editing and permission settings, are captured
by the audit function. Audit records cannot be edited or modified.
Because audit records cannot be altered, a deletion request that touches them is handled by deleting the
underlying contract record and retaining only the audit entry showing that the deletion occurred. We
explain this to customers so they can account for it in their own retention decisions.
3.4 If you are not our customer but your information is in the Service
Contact the organization you dealt with. It decides what happens to that information and it is the right
party to answer you. If you send a request to us instead, we will do one of two things: pass it to the
relevant customer and tell you we have done so, or, where we can identify the customer and the
customer has instructed us to act, respond on the customer’s behalf. We will not delete or change a
customer’s records on the instruction of a third party without the customer’s authority.
4. Artificial intelligence
4.1 Where AI is used
Malbek AI and Malbek BusinessIQ use artificial intelligence to do things such as extract clauses and
metadata from contracts, suggest language, summarize documents and surface insights across a
contract portfolio. Some of this runs on models we license from third parties. These features apply only to
customers who have subscribed to them.
Where you are interacting with an AI system rather than with a person, we tell you so in the product.
Where the Service generates or materially alters text, images or other content, we mark that output as
artificially generated in a machine-readable form so far as it is technically feasible to do so.
4.2 Our commitments on training and confidentiality
– We do not use your data to train the AI models we use. Data submitted to or used with a third-
party AI provider is not used to further train that provider’s models.
– Our agreements with third-party AI providers contain a do-not-train provision. It is a contractual
restriction, not simply a matter of practice.
– Where applicable, we anonymize personal information before using it in conjunction with a
third-party AI tool.
– We do not permit AI providers to use prompts or outputs for their own purposes.
4.3 AI providers
Our AI subprocessors, including Amazon Web Services, Google Document AI and Microsoft Azure AI, are
named at trust.malbek.io/subprocessors together with their location and function. AI subprocessors apply
only to customers who have subscribed to AI-powered services. We give customers advance notice
before adding a new AI provider, in accordance with the Data Processing Addendum.
4.4 Automated decision-making
Malbek does not make decisions about you that produce legal effects or similarly significant effects using
solely automated means, and the Service is not designed to be used that way. Where a feature scores,
ranks or classifies a contract or a party, the output is a recommendation for a person to act on, and a user
can review, override or ignore it.
If that changes, we will tell you before the feature is used on your information, explain what the system
does, what categories of information affect its output and how the output is used, and give you a way to
opt out and to ask for a human review. In Quebec we will tell you at the time an exclusively automated
decision is made, tell you what personal information was used and the principal factors that led to the
decision, and give you the opportunity to submit observations to a member of our staff who can review it.
If you want a person to look at an automated output that affects you, write to privacy@malbek.io.
5. How long we keep information
We keep personal information only as long as we need it for the purpose we collected it for, and then for
as long as we are required to keep it by law or need it to establish, exercise or defend legal claims. The
table below sets out the criteria we use for each category. Where a fixed period applies to a particular
customer, it is set out in that customer’s agreement.
Category How we determine how long to keep it
Customer data in the Service Kept for the term of the customer’s subscription. On termination it is
deleted or returned in accordance with the Data Processing Addendum
and the customer’s agreement.
Backups Kept until the backup cycle in which the data was deleted has been
overwritten. Data removed from the live environment persists in backups
until that cycle completes.
Audit and security logs Kept for as long as we need them for security monitoring, incident
investigation, dispute resolution and our audit obligations. Audit records
within the Service are immutable and are retained for the life of the
customer instance.
Account records for named users Kept for the term of the subscription and then for as long as we need them
to close out billing, support and contractual matters.
Marketing contacts Kept until you unsubscribe or object, after which we keep only what we
need to honor that request. We review contacts periodically and remove
those with no engagement.
Website analytics and cookie data Kept for the lifespan shown for each cookie in the cookie preferences
control on the Site. Where consent applies, we ask again rather than
extending a lifespan.
Support tickets and correspondence Kept for as long as we need them to maintain a service history for the
customer and to respond to any related claim.
Recruiting records Kept for as long as we need them to complete the recruitment process
and to respond to any related claim, unless you ask us to delete them
sooner or agree to be kept on file for future roles.
Billing, tax and accounting records Kept for the period required by applicable tax, accounting and corporate
record-keeping law, and by the relevant limitation period.
Records of privacy requests and
consents
Kept for as long as we need them to demonstrate that we handled the
request properly and honored the choice you made.
6. International transfers
Malbek is based in the United States and our production infrastructure is hosted in the United States. If
you are outside the United States, your personal information will be transferred to and processed in the
United States. Some of our service providers operate in other countries, including Ireland and Sweden,
and personal information may be processed there. The current list, with the location of each provider, is at
trust.malbek.io/subprocessors.
Laws in those countries may not give the same protection as the laws where you live, and personal
information may be accessible to public authorities under those countries’ laws. We do not rely on your
consent to make these transfers. We rely on the following.
From the EEA, the United Kingdom and Switzerland
– Standard contractual clauses. We use the European Commission’s 2021 standard contractual
clauses, with the UK International Data Transfer Addendum for the United Kingdom and the Swiss
adaptations for Switzerland. They are incorporated into our Data Processing Addendum. You can
request a copy, with commercially confidential terms redacted, by writing to privacy@malbek.io.
– Transfer impact assessments. We assess the laws and practices of each destination country and
apply supplementary technical, contractual and organizational measures where they are needed,
including encryption in transit and at rest, access controls, and a commitment to challenge unlawful
government access requests.
From Canada
We transfer personal information to the United States for processing. While it is there it is subject to
United States law, including lawful access by United States courts and government authorities. We use
contractual and security measures designed to provide a comparable level of protection to what Canadian
law requires. Where personal information is handled by a service provider outside Canada, we will tell
you the countries involved and the purposes of the transfer on request, and we carry out a privacy impact
assessment before transferring personal information outside Quebec.
7. Security
We maintain administrative, technical and physical safeguards designed to protect personal information
from unauthorized access, destruction, use, modification and disclosure. These include encryption in
transit and at rest, role-based access control, multi-factor authentication, audit logging, network
monitoring, vulnerability management, penetration testing, background checks on personnel and security
awareness training.
Malbek maintains SOC 1 Type II and SOC 2 Type II attestation. Current reports, our penetration testing
summary, our security and disaster recovery documentation and our control descriptions are available
through the Malbek Trust Center at trust.malbek.io, subject to a confidentiality agreement where the
document requires one.
No method of transmission over the internet and no method of electronic storage is completely secure.
We cannot guarantee absolute security, and you should protect your own account credentials
accordingly.
8. Security incidents
If we become aware of a security incident affecting personal information we hold as a controller, we will
notify affected individuals and the relevant regulators where the law requires it, and we will do so without
undue delay.
If an incident affects customer data, we notify the affected customer without undue delay and within the
period set out in the Data Processing Addendum, and we give the customer the information it needs to
meet its own notification obligations, including the 72-hour deadline that applies to controllers under the
GDPR. Notification is not an admission of fault.
9. Your privacy rights
9.1 Rights we make available to everyone
Wherever you live, and whether or not your local law requires it, you can ask us to:
– Know what personal information we hold about you, where we got it, why we use it, how long we
keep it and who we disclose it to.
– Access a copy of that information, and receive it in a portable, machine-readable format where that
is technically feasible.
– Correct information that is inaccurate or incomplete.
– Delete information we no longer need to keep.
– Opt out of marketing, and of any sale or sharing of personal information or processing for targeted
advertising.
– Limit our use and disclosure of sensitive personal information to what is necessary to provide the
Service.
– Object to or restrict processing we carry out on the basis of legitimate interests, and withdraw
consent where we rely on it.
– Appeal any decision we make on the above.
We will not deny you goods or services, charge you a different price, give you a different quality of
service, or retaliate against you because you exercised a privacy right.
9.2 How to make a request
You can reach us in any of these ways:
– Email privacy@malbek.io.
– Write to Malbek, Attention: Privacy, 300 Carnegie Center Drive, Suite 210, Princeton, New Jersey
08540, United States.
– Call (609) 356-0184.
An authorized agent may act for you if you give them written permission, and we may ask you to confirm
directly that you authorized them. We verify requests before acting on them, which usually means
matching the details in your request against what we already hold and, for sensitive requests, asking for
additional confirmation. We do not use verification information for any other purpose and we delete it
afterwards.
We acknowledge requests promptly and respond within 45 days, or within one month where the GDPR
applies. If a request is complex we may extend that once, by a further 45 days or by up to two months
respectively, and we will tell you why before the original deadline passes. Requests are free unless they
are manifestly unfounded or excessive, in which case we will tell you before doing anything.
If we decline a request, we will tell you why and how to appeal. To appeal, reply to our decision or write to
privacy@malbek.io with "Appeal" in the subject line. We respond to appeals within 45 days. If we deny an
appeal, we will give you a way to complain to your state Attorney General or other competent regulator.
If your information is in the Service because one of our customers put it there, see Section 3.4 first.
9.3 United States
If you live in a state with a comprehensive privacy law, the rights in Section 9.1 are available to you as a
matter of law. As of the effective date of this policy those states are California, Colorado, Connecticut,
Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire,
New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah and Virginia. Annex A sets out the points on
which those laws differ. If your state is not listed, write to us anyway. We generally extend the same rights
to everyone.
California residents: Annex B lists the categories of personal information we have collected in the
preceding 12 months, the sources, the business and commercial purposes, and the categories of third
parties we disclose each category to. California residents may also request the specific pieces of
personal information we hold, not only the categories, and may designate an authorized agent.
Nevada residents may direct us not to sell covered information. We do not sell covered information as
Nevada defines it, but you can submit a request to privacy@malbek.io.
9.4 European Economic Area, United Kingdom and Switzerland
In addition to the rights in Section 9.1, you have the right to lodge a complaint with a data protection
supervisory authority. You can complain to the authority in the country where you live, where you work, or
where you believe the problem occurred. In the United Kingdom the authority is the Information
Commissioner’s Office. In Switzerland it is the Federal Data Protection and Information Commissioner.
You have the right to object at any time to processing based on our legitimate interests. If you object to
direct marketing we will stop, with no balancing exercise. If you object to anything else we will stop unless
we can demonstrate compelling legitimate grounds that override your interests, or we need the
information for legal claims.
Where we rely on your consent for a cookie, a marketing message or anything else, you can withdraw it
at any time without affecting what we lawfully did beforehand.
9.5 Canada
We handle personal information in accordance with the Personal Information Protection and Electronic
Documents Act and, where they apply, the private-sector privacy laws of Quebec, Alberta and British
Columbia.
– Consent. We identify the purposes for collection at or before the time we collect. We rely on express
consent for sensitive information and for commercial electronic messages, and on implied consent
only where the purpose would be obvious to a reasonable person and the information is not
sensitive.
– Access and correction. You may ask what personal information we hold, how we have used it and
to whom we have disclosed it, and you may challenge its accuracy.
– Portability. If you are in Quebec, you may ask us to give you the computerized personal information
you provided to us in a structured, commonly used technological format, or to transmit it to another
organization.
– Profiling technology. If you are in Quebec and we use technology that identifies, locates or profiles
you, we will tell you and tell you how to turn it off.
– Challenging our compliance. You may challenge our compliance with these principles by writing to
privacy@malbek.io. We investigate every complaint and, if it is justified, we take appropriate action,
including amending our policies and practices.
If you are not satisfied with our response you may complain to the Office of the Privacy Commissioner of
Canada, 30 Victoria Street, Gatineau, Quebec K1A 1H3, priv.gc.ca. In Quebec you may complain to the
Commission d’accès à l’information du Québec. In Alberta and British Columbia you may complain to the
provincial Information and Privacy Commissioner.
10. Children
The Service is business software. It is not directed to children, and only people aged 18 or over may use
it or register for an account. We do not knowingly collect personal information from anyone under 18. If
we learn that we have, we delete it. If you are a parent or guardian and you believe your child has given
us personal information, write to privacy@malbek.io and we will remove it.
11. Links to other sites
The Site and the Service contain links to sites we do not operate. If you follow one, you leave our control.
We are not responsible for the content or the privacy practices of any third-party site, and we encourage
you to read the privacy policy of every site you visit.
12. Law enforcement and legal process
We may disclose personal information where we are legally required to, for example in response to a
subpoena, court order, warrant or other valid legal process, or where disclosure is necessary to protect
the security or integrity of the Service, to investigate suspected fraud or misuse, or to protect the rights,
property or safety of Malbek, our customers or the public.
When we receive a demand for customer data, we:
– Review it for validity and scope, and require the requesting party to follow proper legal process.
– Challenge demands that are overbroad, defective or unlawful.
– Redirect the requesting party to the customer where the customer is the appropriate party to
respond.
– Notify the affected customer before disclosing anything, unless we are legally prohibited from doing
so, in which case we notify as soon as the prohibition lifts.
– Disclose no more than the demand actually requires.
13. Business transactions
If Malbek is involved in a merger, acquisition, financing, reorganization, sale of assets, bankruptcy or
insolvency, personal information may be transferred or disclosed as part of that transaction or as part of
the diligence leading up to it, subject to confidentiality obligations. Where personal information would
become subject to a different privacy policy, we will give notice before that happens and, where the law
requires consent, we will ask for it.
14. Google API limited use
Malbek’s use and transfer of information received from Google APIs to any other application adheres to
the Google API Services User Data Policy, including its Limited Use requirements. We use Google user
data only to provide or improve the user-facing features the user requested. We do not transfer it to build
advertising profiles, sell it or use it for advertising. Human review of Google user data occurs only with the
user’s consent, for security purposes, to comply with law, or on aggregated and anonymized data for
internal operations.
15. Accessibility and alternative formats
This policy is published in HTML and follows generally recognized accessibility standards, including the
Web Content Accessibility Guidelines version 2.1 at level AA. If you need it in another format, including
large print, plain text or a translated version, write to privacy@malbek.io and we will provide one at no
cost.
16. Changes to this policy
We update this policy as our practices, our products and the law change. The effective date and the last-
updated date appear at the top. Earlier versions are available on request from privacy@malbek.io.
If we make a material change, we will give notice at least 30 days before it takes effect, by email to
account administrators and by a prominent notice on the Site. If a change would result in our using
personal information we already hold in a materially different way from the way we described when we
collected it, we will ask for your consent before doing so rather than relying on notice alone.
Non-material changes, such as correcting a typographical error or updating a contact address, take effect
when posted.
17. How to contact us
For anything to do with this policy, your personal information or a privacy request:
Contact Details
Privacy requests and questions privacy@malbek.io
Malbek, Attention: Privacy, 300 Carnegie Center Drive, Suite 210, Princeton,
New Jersey 08540, United States
(609) 356-0184
Security, compliance and audit
reports
privacy@malbek.io
trust.malbek.io
General Inquiries info@malbek.io
(609) 356-0184
If you have a complaint, tell us first. We investigate every complaint and will tell you what we found and
what we did about it. You can also go to a regulator directly: your state Attorney General in the United
States, your supervisory authority in the European Economic Area, the Information Commissioner’s Office
in the United Kingdom, or the Office of the Privacy Commissioner of Canada or the Commission d’accès
à l’information du Québec in Canada.
Annex A: United States state privacy rights
The rights in Section 9.1 are available to residents of every state listed below. This annex sets out the
points on which the state laws differ, so you can see what applies where you live. We respond to requests
within 45 days and to appeals within 45 days in every state, which meets or exceeds each state’s
deadline.
State What is specific to this state
California You may request the specific pieces of personal information we hold, not only the
categories. You may limit our use of sensitive personal information. Annex B contains
the itemized disclosures required by section 1798.130(a)(5) of the Civil Code.
Authorized agents may act for you with written permission.
Colorado You may opt out of profiling in furtherance of decisions that produce legal or similarly
significant effects. We honor universal opt-out mechanisms. If we deny an appeal we
will tell you how to contact the Attorney General.
Connecticut As Colorado. Consent is required before processing sensitive data, and we honor
universal opt-out mechanisms.
Delaware You may ask for a list of the categories of third parties to whom we have disclosed
personal information. We honor universal opt-out mechanisms.
Florida Rights apply where the Florida Digital Bill of Rights applies to us. You may opt out of the
collection of personal data through voice or facial recognition features, which we do not
use.
Indiana You may ask for either a copy of your personal data or a representative summary of it.
Iowa Iowa law does not provide a correction right or an opt-out of profiling. We provide
correction to Iowa residents as a matter of policy.
Kentucky Rights follow the Virginia model, including the right to appeal.
Maryland We do not sell sensitive personal data, and we collect and process personal data only
as reasonably necessary to provide the product or service you requested. We do not
sell the personal data of anyone we know to be under 18.
State What is specific to this state
Minnesota You may ask us to disclose the personal data used in profiling and, where a profiling
decision was adverse, the reason for it and what you could have done differently. You
may also ask for a list of the specific third parties to whom we have disclosed your
personal data.
Montana We honor universal opt-out mechanisms.
Nebraska We honor universal opt-out mechanisms. Rights follow the Texas model.
New Hampshire We honor universal opt-out mechanisms.
New Jersey Our home state. We honor universal opt-out mechanisms and obtain consent before
processing sensitive data, including financial account information.
Oregon You may ask for a list of the specific third parties to whom we have disclosed your
personal data, not only the categories. We honor universal opt-out mechanisms and
confirm when an opt-out has been applied.
Rhode Island Where a business sells personal data, Rhode Island requires it to be named in this
notice. We do not sell personal data.
Tennessee Rights follow the Virginia model, including the right to appeal.
Texas We honor universal opt-out mechanisms. We do not sell sensitive or biometric personal
data, so the notices Texas prescribes for those sales do not apply to us.
Utah Utah law does not provide a correction right or an appeal right. We provide both to Utah
residents as a matter of policy.
Virginia You may opt out of profiling in furtherance of decisions producing legal or similarly
significant effects, and you may appeal a denied request.
Annex B: Categories of personal information under California law
This annex covers the 12 months before the last-updated date at the top of this policy and applies to
information Malbek collects as a business. It does not cover customer data, for which Malbek is a service
provider and the customer is the business. We do not sell personal information and we do not share it for
cross-context behavioral advertising. We do not have actual knowledge of selling or sharing the personal
information of consumers under 16 years of age. Retention for each category is described in Section 5.
Statutory category Collected Business or commercial
purpose
Categories of third parties we
disclose it to
Identifiers (name, alias,
postal address, email, IP
address, account name,
unique or online identifier)
Yes Providing and securing the
Service, responding to
enquiries, marketing, billing,
fraud prevention and legal
compliance.
Cloud hosting, CRM and
marketing platforms, analytics
and intent data providers,
support tools, payment
providers, professional advisers.
Customer records
information (name,
address, telephone
number, financial or
payment information)
Yes Billing, collections, accounting
and tax.
Payment and billing providers,
professional advisers, tax
authorities where required.
Characteristics of
protected classifications
No Not collected. Where a job
applicant volunteers
demographic information, it is
Not disclosed.
Statutory category Collected Business or commercial
purpose
Categories of third parties we
disclose it to
kept separate and used only for
aggregate reporting.
Commercial information
(records of products or
services purchased or
considered)
Yes Account management,
renewals, customer success
and product analytics.
CRM and marketing platforms,
cloud hosting, professional
advisers.
Biometric information No Not collected. Not disclosed.
Internet or other electronic
network activity (browsing
and search history on our
Site, interaction with our
Site)
Yes Operating and securing the Site
and Service, diagnosing faults
and measuring performance.
Analytics providers, cloud
hosting.
Geolocation data Approximate
only
Derived from IP address and
used for security, fraud
prevention, routing and coarse
regional analytics. We do not
collect precise geolocation.
Analytics providers, cloud
hosting, security providers.
Audio, electronic, visual or
similar information
On recorded
calls only
Support, training and quality
assurance. We tell you before
recording and you can decline.
Meeting and webinar platform
providers, support tools.
Professional or
employment-related
information
Yes Assessing job applications,
managing the commercial
relationship and verifying
authority to bind a customer.
Applicant tracking system, CRM,
professional advisers.
Education information Applicants
only
Assessing job applications. Applicant tracking system.
Inferences drawn from the
above (preferences,
characteristics, behavior,
aptitudes)
Yes Prioritizing outreach, tailoring
content and improving the Site
and Service.
CRM and marketing platforms,
analytics and intent data
providers.
Sensitive personal
information (government
identifiers, account log-in
credentials, precise
geolocation, contents of
communications, racial or
ethnic origin, religion,
union membership, health,
sex life or sexual
orientation, genetic or
biometric data)
Log-in
credentials
only
Authenticating users and
securing accounts. This is a
permitted purpose under section
1798.121, and we do not use or
disclose sensitive personal
information for any purpose that
would trigger the right to limit.
Cloud hosting and identity
providers only.
Annex C: Cookies and similar technologies
The categories below describe what we use. The exact name, provider and lifespan of every cookie in
use is listed in the cookie preferences control on the Site, which is generated from a live scan and kept
current automatically.
Category What it does Consent required
Strictly necessary Keeps you signed in, balances load, remembers your
cookie choices, and protects against fraud and
automated abuse. Includes our consent management
platform and bot protection.
No. The Site cannot work
without these.
Preferences Remembers settings such as language and region so
you do not have to set them again.
Yes, in the EEA, the UK,
Switzerland and anywhere
else local law requires it.
Analytics and
performance
Tells us which pages are visited, how people move
through the Site and where things break. Includes
Google Analytics.
Yes, in the EEA, the UK,
Switzerland and anywhere
else local law requires it.
Advertising Not used. We do not use cookies or similar
technologies for cross-context behavioral advertising
or targeted advertising.
Not applicable.
Embedded content Delivers third-party content such as video players,
forms and the Malbek Klix agreement viewer. These
providers may set their own cookies.
Yes, in the EEA, the UK,
Switzerland and anywhere
else local law requires it.