1. Introduction
This Privacy Policy explains how Maxor Global LLC ("Maxor", "we", "us", or "our") handles personal information when you visit maxorconnect.com, request early access, contact us, or use the MaxorConnect platform (together, the "Service"). We designed MaxorConnect as a system of intelligence, not a system of surveillance: we collect what is needed to run the product, we never sell personal information, and we never use your Customer Data to train third-party foundation models.
MaxorConnect is distributed in Canada by Maxor Technologies Inc., which acts solely as a reseller and does not own or control Customer Data processed in the Service. The controller / processor roles below apply to Maxor as the service provider.
If you do not agree with this Policy, please do not use the Service. For questions or privacy requests, contact [email protected].
2. Roles: controller & processor
Customer Data (we are the processor). When your organization uses MaxorConnect, you (the customer) are the controller of the business content you put into the Service — CRM records, tickets, documents, messages, marketing assets, time entries, configuration and similar content ("Customer Data"). We act as your processor (or "service provider" under US state privacy laws): we host and process Customer Data only to provide the Service, on your documented instructions, as described in this Policy, our Terms, and any Data Processing Addendum ("DPA") you sign with us. Our public DPA is available at /legal/dpa.
Account, site and commercial data (we are the controller). We are the controller of account administration data (user accounts, seat assignments, roles, billing contacts), security and audit logs we generate to protect the Service, website analytics, and early-access / contact-form submissions we collect for our own sales, onboarding and support.
Enterprise customers may request a countersigned DPA (including Standard Contractual Clauses where required) by emailing [email protected]. Nothing in a marketing-site summary replaces a signed order form or DPA for enterprise deployments.
3. Categories of personal data
Depending on how you interact with us, we may process the following categories of personal data. We do not intentionally collect special categories of data (health, biometric templates, precise geolocation for tracking, children's data, or government ID numbers) as part of the core Service unless you independently choose to store such content in Customer Data fields you control.
| Category | Examples | Typical sources |
|---|---|---|
| Identity & contact | Name, work email, phone, company, job title, locale preference | Account signup, early-access forms, contact forms, admin invites |
| Account & authentication | User ID, org membership, roles/ABAC attributes, session tokens, MFA status, API keys (hashed) | Product signup, SSO/OAuth you enable, admin configuration |
| Billing & commercial | Plan, seat count, invoice metadata, partial payment identifiers (last4/brand via processor) | Checkout, order forms, Stripe as payment processor |
| Customer Data (content) | CRM records, tickets, emails/docs you store, notes, files, agent configs | You and your users; integrations you connect |
| Usage & product telemetry | Feature usage, page/route events inside the app, performance metrics, error traces (non-content) | Automatically when you use the Service |
| Device & technical | IP address, user agent, approximate location (city/country), browser/OS, referrer | Automatically on website and app requests |
| Security & audit | Sign-in events, access decisions, admin actions, rate-limit and abuse signals | Authentication, ABAC enforcement, monitoring |
| Communications | Support tickets, email threads with us, feedback, survey responses | You, when you contact us or reply |
| Marketing-site analytics | Aggregate page views, referrers, country (cookieless; no cross-site ID) | Plausible Analytics on the marketing site |
| Integration payloads | Data returned by Microsoft 365, Google Workspace, Ads, LinkedIn, Stripe, Apollo, etc. | Only when you authorize a connection |
4. How we collect information
Information you provide
- Account & contact details — name, work email, company, role, and anything you enter in contact or early-access forms.
- Billing information — plan, seat count and payment details, processed by our payment provider (we do not store full card numbers on our servers).
- Content you create — records, files, messages and configuration you and your team store in the Service (Customer Data).
- Support & feedback — messages you send us and product feedback you choose to share.
Information collected automatically
- Usage & device data — pages and features used, approximate location, browser and device type, collected to operate, secure and improve the Service.
- Cookieless analytics — aggregate website statistics via Plausible Analytics, which sets no cookies and collects no cross-site identifiers. See our Cookie Policy.
- Security logs — authentication events, access decisions and audit trails needed to enforce org isolation, ABAC and abuse prevention.
Information from integrations you connect
When you choose to connect a third-party service (for example Microsoft 365, Google Workspace, Apollo or Stripe), we process the data those services return, strictly to provide the features you enabled and only within the scope you authorize. You can disconnect integrations in product settings; residual copies may remain in backups for a limited retention window.
Advertising-platform integrations (Google Ads & LinkedIn)
The MaxorConnect marketing module can connect to advertising accounts you own — currently Google Ads and LinkedIn — through OAuth authorization you grant and can revoke at any time. Once connected, we read your campaign, spend and performance data to power marketing intelligence for your own organization. We send data back to a platform only when you turn on a measurement or audience feature, and only the data you direct — for example a conversion signal tied to an ad click, or an audience list you build from your own records. For these transfers we act on your instructions as a processor; you are responsible for having the legal basis and any consents required to share that data with the platform.
Google API Services Limited Use. MaxorConnect's use and transfer of information received from Google APIs, including the Google Ads API, adhere to the Google API Services User Data Policy (developers.google.com/terms/api-services-user-data-policy), including its Limited Use requirements. Information obtained through the LinkedIn Marketing API is used solely to provide the features you enable and in line with LinkedIn's API terms — we never use it for any other purpose, and we never use it to train third-party AI models.
5. Purposes & legal bases
We use personal information for the purposes below. Where the GDPR, UK GDPR or similar laws apply, the primary legal bases are indicated. Multiple bases may apply to the same processing.
| Purpose | Examples | Primary legal basis (EEA/UK) |
|---|---|---|
| Provide the Service | Accounts, orgs, seats, hosting Customer Data, APIs, exports | Contract (Art. 6(1)(b)) |
| Security & integrity | Auth, ABAC, fraud/abuse prevention, audit logs, incident response | Legitimate interests / legal obligation |
| Intelligence features | Heisen detect → recommend → verify on your org's data; generative escalation via Grok (xAI) | Contract; legitimate interests (product operation) |
| Billing & fraud prevention | Invoices, payment processing, dunning, chargeback defense | Contract; legitimate interests; legal obligation |
| Customer support | Respond to tickets, early-access onboarding, technical assistance | Contract; legitimate interests |
| Product improvement | Aggregate/de-identified metrics, reliability, UX (not training third-party models on Customer Data) | Legitimate interests |
| Service communications | Security alerts, product changes, billing notices | Contract; legitimate interests |
| Optional product/marketing mail | Product updates you can unsubscribe from | Consent and/or soft opt-in where permitted |
| Legal compliance | Tax, accounting, lawful requests, enforcing agreements | Legal obligation; legitimate interests |
Legitimate interests. Where we rely on legitimate interests, we balance our interest in running a secure, reliable B2B product against your rights. You may object as described in §10. We do not use Customer Data for cross-context behavioural advertising.
6. AI processing & your data
MaxorConnect runs on Heisen, our proprietary intelligence stack. Most computation is deterministic (engines and rules) and runs on your data within your organization's tenancy. When a task escalates to generative AI, the underlying model is Grok (provided by xAI) under a governed contract — the generative layer behind Heisen. See Sub-processors.
- Grok / xAI is the production generative path. We do not route Customer Data in the Service to Anthropic or other non-listed model providers. Tools used strictly for internal software development (for example Anthropic during engineering) are not Service sub-processors and do not process your Customer Data.
- No third-party model training on Customer Data. We do not use your Customer Data or personal information to train third-party foundation models. We do not sell prompts or outputs as training sets.
- No training of models we do not own on Customer Data without a separate written agreement. Product improvement uses aggregate, de-identified or non-content signals where feasible — not your CRM rows as foundation-model fuel.
- Independence / hallucination firewall. Material AI outputs are subject to independence and quality checks before they surface; AI actions are written to your audit trail.
- You control agent scope. Automated agents operate only within the access policies, ABAC attributes and approval tiers (autonomous → supervised → sign-off) you configure.
- Human review. AI outputs are recommendations, not professional, legal, tax or medical advice; you remain responsible for decisions you take.
8. International transfers & residency
We are based in the United States and use sub-processors located in the US, the EU/EEA, the UK and Canada. Where personal data is transferred from the EEA, UK or Switzerland to a country not deemed adequate, we rely on appropriate safeguards — primarily the European Commission's Standard Contractual Clauses (and UK International Data Transfer Addendum where applicable), plus supplementary measures as needed.
EU, UK and Canadian customers are served with automatic regional data residency options for core Customer Data stores where the product supports them. Enterprise agreements may specify stricter residency, single-region lock or segregation requirements. Transfers of controller-side website and billing data may still involve the US.
Details of processing, transfer mechanisms and sub-processor locations are further described in our DPA (/legal/dpa) and Sub-processors list.
9. Retention, export & deletion
We keep personal information only as long as needed for the purposes above, including legal, tax and accounting obligations, dispute resolution and enforcement of agreements.
- Active accounts — Customer Data is retained while your subscription or early-access tenancy is active, subject to your own deletion inside the product.
- After termination — you may export Customer Data while the account is active and for a commercially reasonable export window after termination (typically up to 30 days if we still hold the data), subject to legal holds and unpaid fees where permitted by law.
- Deletion — after the export window, we delete or irreversibly anonymize Customer Data within a commercially reasonable period (typically 30–90 days), except backups that age out on a rolling schedule and records we must keep by law (e.g. invoices).
- Controller-side data — early-access leads, support tickets and billing records are retained for the period needed for sales follow-up, support history and statutory retention (often multi-year for tax).
- Enterprise — custom retention schedules can be agreed in writing.
10. Your privacy rights (general)
Depending on where you live, you may have the right to access, correct, delete, port, restrict or object to processing of your personal information, to withdraw consent, and to lodge a complaint with a supervisory authority. We will not discriminate against you for exercising a privacy right.
How to exercise. Email [email protected] with "Privacy request" in the subject line, describe the right you wish to exercise, and provide enough information for us to verify your identity (we may request additional verification to prevent fraud). We respond within the timeframe required by applicable law (for example, generally one month under GDPR, extendable where permitted; 45 days under CCPA/CPRA, extendable once).
Processor requests. If we process your data only as a processor for a MaxorConnect customer (for example your employer), we will direct you to that customer where appropriate, or assist them to respond under our DPA.
Authorized agents. Where law allows an authorized agent to submit a request on your behalf, we will require proof of authorization and may still need to verify you directly.
11. EEA, UK & Swiss rights (GDPR)
If the GDPR, UK GDPR or Swiss FADP applies, you have the rights of access, rectification, erasure, restriction, portability, objection (including to processing based on legitimate interests), and withdrawal of consent. You also have the right to lodge a complaint with your local supervisory authority (for example the CNIL, ICO, or your EU member-state DPA).
Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal. Where based on legitimate interests, you may object; we will stop unless we demonstrate compelling legitimate grounds or need the data for legal claims.
For EEA/UK questions, contact [email protected]. We have not appointed an EU Article 27 representative solely via this Policy; enterprise customers may negotiate representative language in a DPA if required for their compliance program.
12. California & other US state rights
California (CCPA/CPRA). California residents have the right to know/access, delete, correct, and opt out of sale or sharing of personal information for cross-context behavioural advertising, and to limit use of sensitive personal information where applicable. We do not sell personal information and we do not share personal information for cross-context behavioural advertising. We have no actual knowledge of selling or sharing the personal information of consumers under 16. We do not use or disclose sensitive personal information for purposes that require a right to limit under CPRA, beyond what is necessary to provide the Service.
Notice at collection. The categories we collect, purposes, and retention practices are described in §§3–9. We collect these categories for business purposes (providing the Service, security, billing, support) and commercial purposes only as listed there — not for selling data.
Other US states. Residents of states with comprehensive privacy laws (including, as applicable, Virginia, Colorado, Connecticut, Utah, Texas and others as they come into force) may have similar rights of access, deletion, correction, portability and opt-out of targeted advertising or sale. Because we do not sell personal information or engage in cross-context targeted advertising with marketing-site cookies, the primary practical rights are access, correction and deletion of account and lead data we control.
Do Not Sell or Share / GPC. Because we do not sell or share personal information for cross-context behavioural advertising, we treat Global Privacy Control and similar signals as confirmation of our existing non-sale/non-share posture for controller-side web data. To exercise other rights, email [email protected].
Service provider / processor role. For Customer Data, we act as a service provider / processor to your business customer. Consumer requests about Customer Data should generally go to that business; we assist them under the DPA.
13. Canada & Québec (Law 25)
Residents of Canada have rights of access and correction under applicable federal and provincial privacy laws. Residents of Québec have additional rights under Law 25 (Act to modernize legislative provisions as regards the protection of personal information), including rights relating to access, rectification, de-indexation in certain cases, and transparency about automated decision-making that significantly affects them.
Technologies used solely to identify, locate or profile a person must be deactivated by default under Law 25. Our marketing site uses cookieless analytics and only strictly-necessary cookies — there is no advertising profiler to switch off. Material automated decisions inside MaxorConnect remain under your organization's policies and human approval tiers for high-impact agent actions.
The person responsible for the protection of personal information (Québec) may be reached at [email protected] (privacy).
14. Security & breach notice
We protect personal information with organization-level isolation, attribute-based access control (ABAC) with step-up MFA on sensitive actions, encryption in transit (TLS) and at rest, least-privilege operational access, and a full audit trail. Our controls are built to SOC 2 and ISO 27001 standards — this is a statement of engineering practice, not a claim of current third-party certification unless we publish a current report under NDA or on this site.
No method of transmission or storage is perfectly secure. You are responsible for safeguarding credentials, configuring roles thoughtfully, and promptly revoking access for departing users.
If we become aware of a personal-data breach that is likely to result in a risk to individuals, we will notify affected customers and, where required, competent authorities without undue delay, consistent with applicable law (including GDPR Arts. 33/34 and Law 25 where they apply). Our DPA sets additional contractual timelines for processor-side incidents.
15. Children
MaxorConnect is a business product directed to organizations and professionals. It is not directed to children under 16, and we do not knowingly collect their personal information. If you believe a child has provided us personal information, contact ${EMAIL} and we will delete it.
16. Changes to this Policy
We may update this Policy as the Service evolves or the law changes. We will post the new version here with a revised Last updated date. For material changes that reduce your rights or expand processing in a significant way, we will provide additional notice (for example by email to account admins or an in-product banner) with reasonable advance notice where practicable.
17. Contact us
Questions, complaints or privacy requests: email [email protected] or write to Maxor Global LLC, 2915 Ogletown Road #5188, Newark, Delaware 19713, USA.
For Québec Law 25 matters, address the person responsible for the protection of personal information at [email protected] (privacy).