Legal

Privacy Policy

What we do with personal information, and the rights you have over it

Sylvent Corporation, trading as effect.com

Last updated: August 23, 2026

1. Who we are and what this policy is

Sylvent Corporation, a Delaware corporation with its registered office at 131 Continental Drive, Suite 301, Newark, DE 19713, United States, trading as effect.com (“Effect”, “we”, “us”, “our”), is the party responsible for the personal information described here. In Mexican terms, Sylvent Corporation is the responsable, and this document is the aviso de privacidad integral.

This policy covers our website at effect.com and related domains, our writing at blog.effect.com, the client workspace at app.effect.com, our software and APIs, and our communications. Together these are the “Services”.

What Effect does. Effect sells analytics software to non-bank lenders. A lender connects the systems it already operates; the platform measures that lender’s own loan book on a fixed set of checks and reports on it continuously, so the institution financing that lender reads the same figures the lender does. Effect is not a bank, a lender, a broker-dealer, an investment adviser or a credit rating agency. It does not originate loans, does not extend credit, does not make or participate in credit decisions, and does not hold anyone’s funds.

Effect is not a credit bureau and does not act as one. We are not a sociedad de información crediticia, and we are not and cannot become a Usuario of one: Mexican law reserves that class to entities we do not belong to. Where a client’s portfolio data reaches us we act as a service provider to that client, with the confidentiality and purpose-limitation duties that role carries. We do not hold, query, resell or enrich credit histories about identified borrowers, we do not consult Buró de Crédito or Círculo de Crédito, and we assign no credit score, grade or rating to any borrower, lender or instrument. Where a borrower’s information reaches our systems at all, it does so inside a lender’s own portfolio data, and section 9 governs it.

Where we are. We work from the United States and our systems run there. Effect has no establishment, office, staff or agent in Mexico and carries on no activity there. The lenders our software serves operate in Latin America, and the institutions that finance them sit in North America and Europe.

Two roles, and the difference matters. For information we handle as a business (website visitors, people who write to us, prospective and current clients), we decide why and how, and this policy governs it. For personal information inside a client’s portfolio data, the client decides why and how; we act only on that client’s instructions, and the client’s own privacy notice governs it. Section 9 sets out the second role in full.

Which laws this policy is written to. This policy is designed to address applicable requirements under Mexico’s federal data protection law for private parties, under the GDPR as it applies in the European Economic Area and in the United Kingdom, and under United States state privacy laws, principally California’s. Which of them applies to any particular processing depends on the circumstances, and this policy does not decide that question for you. Where a regime applies, the section written for it governs: section 4 for the legal bases, section 6 for transfers, section 10 for rights, and section 11 for California and the other United States states.

2. Information we collect

Information you give us. When you fill in a form, ask us for a call, write to us, or otherwise get in touch, we collect what you submit: your name, business email, phone number, company name, when you say you tend to be free, and the contents of your message. There is no scheduling calendar on this site: a request for a call is a form on our own domain, and a person reads it and writes back to settle the time. Once a time is agreed, the meeting itself is created in a third-party video conferencing service, which receives your name, your email address and the subject of the call in order to send the invitation and the link. What you submitted is recorded in our own systems, together with the page you submitted from, so that whoever takes the call has read it beforehand.

Account information. If you are given access to the workspace: your name, business email, employer, role, the account that approved you, and the record of your sign-ins. Authentication is delegated to our identity provider, so we hold no password in any form.

Where a visit came from. Two separate things, and the difference is the cookie card. On every page load our own server records that a page was read, with the address of the page, which of our sites it was on, and the campaign parameters on the link that brought you. That record is first-party, goes to no vendor, and is not tied to you: unless you have granted analytics, no identifier is attached to it and it cannot be joined to any other visit. Separately, and only if you have granted analytics, a cookie named effect-ft stores which link first brought your browser to us, together with a random identifier so that a later visit can be recognised as the same browser. It lasts one year, it carries nothing you typed, and it is sent to no third party.

Information collected automatically. When you use the website we may collect technical and usage data: IP address, device and browser type, pages viewed, referring URLs and similar diagnostics, including through cookies. With your consent this also includes a recording of your visit. Everything about that is set out in our Cookie Policy, which names the cookies and storage keys this site can place, the vendor behind each one, what it is for and how long it lasts, and which forms part of this policy. Where a third party sets a cookie from its own domain inside content we place in a page, that policy names the third party and the cookies we have observed it set; the list is the vendor’s to change, not ours.

Access and activity logs. Access to the workspace is logged: who opened what, when, from which address and with which browser. The record carries the email address of the account, the IP address the request came from and the browser string. We keep these because a lender entrusting us with its portfolio is entitled to know who has read it. The record of your cookie answer carries the same two technical details, for the same reason: an answer nobody can attribute to a request is not evidence of anything.

Information from third parties. We may receive business-contact or enrichment information from analytics, hosting and business-information providers.

Financial and patrimonial data. Mexican law treats information about a person’s finances and assets as requiring express consent, given separately and in writing. We do not ask any individual for such data through this website, and we do not process it about any individual on our own account. Where financial information about a borrower exists inside a client lender’s portfolio data, section 9 governs it and the lender, not Effect, is responsible for holding the consent.

What we do not ask for. We collect no health, biometric, religious, political or trade-union information through the website. We do not ask any individual for a bank account number, a card number, a CURP or an RFC through this website. The one category of sensitive information we do handle is the credential that lets an authorised person into the workspace, and section 11 says how it is treated.

3. Why we use it, split into necessary and optional

Mexican law requires this split, and it is a useful one everywhere, so we make it once and apply it to all readers.

Necessary purposes. These are what makes the relationship work, and you cannot refuse them while continuing to use the Services.

  • Answering your enquiries, scheduling meetings, and providing the Services.
  • Creating and operating accounts, authenticating sign-ins, and maintaining the access logs described above.
  • Operating, securing and maintaining the website and the workspace, including detecting and preventing fraud, abuse and technical failure, and reporting technical errors so that they can be fixed.
  • Recording and being able to demonstrate the cookie answer you gave, as the Cookie Policy describes.
  • Meeting legal, tax and accounting obligations, and responding to lawful requests.

Secondary purposes. These are not necessary. Refusing them costs you nothing and changes nothing else.

  • Measuring how the website is read and used, through the analytics and recording purposes described in the Cookie Policy.
  • Placing third-party embedded content. Since 3 September 2026 this covers nothing on the site: the booking calendar was the only embed and it was removed, so the choice remains available and refusing it currently changes nothing. The Cookie Policy describes the purpose and what would fall under it.
  • Sending you information about our products, updates and events.

How to refuse the secondary purposes. For analytics, recording and embeds, press Reject on the cookie card, or open Cookie preferences in the footer of any page and turn them off. For our own messages, use the unsubscribe link in any message, or write to legal@effect.com with the words “no marketing”. You may refuse any of them without giving a reason, at any time, including before we ever contact you, and refusing has no effect on the Services you receive.

Inside the client workspace, the card is not shown. If you reach app.effect.com without passing through our website, you will not see the cookie card. Nothing that waits for it runs there: no analytics, no session recording and no embed is loaded inside the workspace, and if you have never answered the card anywhere, the answer is read as a refusal. What does run there is what runs on any signed-in system, and section 5 lists it: hosting, the database and the sign-in session, the anti-abuse check on the sign-in and registration screens, error reporting, and the access log. You can still change a previous answer from Cookie preferences in the footer of our website.

Where the GDPR applies, each activity has one basis and they are not interchangeable.

Consent, art. 6(1)(a)
What it carries: Analytics, session recording and third-party embeds, which are the three purposes the cookie card asks about. None of the three runs before you grant it; each can be granted or refused on its own; and when you withdraw, collection under it stops. Section 7 of the Cookie Policy says, tool by tool, exactly what withdrawal does and what it cannot do.
Contract, art. 6(1)(b)
What it carries: Providing the Services to a client and to the people that client authorises, including creating and running an account.
Legitimate interests, art. 6(1)(f)
What it carries: Operating and securing the website and the workspace; technical error reporting, which runs on every page rather than behind the cookie card, for the reason given in section 5; the anti-abuse check on the sign-in and registration screens; keeping the record of your cookie answer; the first-party record that a page was read, described in sections 2 and 7, which is sent to nobody; access logging; and business-to-business contact with people who asked to hear from us. Our interest is in running, defending and being able to account for the Services. You may object at any time under art. 21.
Legal obligation, art. 6(1)(c)
What it carries: Tax and accounting records, and lawful requests.

Where Mexican law applies, this policy is the privacy notice the law requires, made available to you before your data is collected. The basis on which we act is not one blanket answer: it depends on the category of data and on the purpose it serves.

  • For the ordinary business-contact data described in section 2, name, business email, telephone number, employer and the content of your message, the necessary purposes in section 3 are those without which the relationship you asked for cannot be performed, or which a legal obligation requires of us.
  • For the secondary purposes, consent is taken through the cookie card and the unsubscribe mechanism, and is recorded together with the version of this notice that was on your screen when you gave it.
  • Financial or patrimonial data, and personal information about a lender’s borrowers, are not collected through this website and are not covered by this section. Where they exist, they reach us only inside a client’s portfolio data, the client is the responsable for them, and section 9 governs them, including the consent that lender is required to hold.

Conclusion. No analytics, no session recording and no third-party embed runs on this website before you answer the cookie card. Four things do run without waiting for an answer, and each is named rather than hidden: what makes the site and the workspace work; the record of the answer you gave, without which a refusal could not be proved and you would be asked again on every page; the first-touch mark described in sections 2 and 7; and technical error reporting, which is loaded on every page so that it can catch a failure that happens while the page is still loading. The last three rest on legitimate interests rather than on consent, section 5 says what each receives, and you may object to any of them under art. 21. Nothing you refuse is needed to use the Services.

5. Who receives it

We disclose personal information to the categories of recipient below. Each is engaged under written terms that limit it to the purpose we engaged it for, acting as a processor under the GDPR, an encargado under Mexican law and a service provider or contractor under California law, rather than as a party free to use your information for its own purposes.

Hosting and content delivery
What it receives: Every request the website and the workspace serve, because it is what serves them. This includes your IP address, the page you asked for and your browser string, which any host necessarily sees.
When: Always
Database, storage and authentication
What it receives: The workspace database, the files a client uploads into it, and the sign-in session that keeps you signed in. Your password is set and checked here rather than by us, and is held only as a cryptographic hash.
When: Always, for the workspace
Error and diagnostic monitoring
What it receives: A technical report when our software fails: the error, the page with the query string removed, and the software version. No cookie, no account, no advertising identifier, and no field you typed. Because the monitor is loaded on every page so that it can catch a failure during page load, its provider also sees the connection your browser makes to it, which carries your IP address at the network layer.
When: Loaded on every page; sends a report when something breaks
Bot and abuse prevention
What it receives: Your IP address, and the signals its own script reads from your browser to tell a person from a machine, for the anti-abuse check on the sign-in and registration screens. No field you typed. These are the only two screens it runs on.
When: On those two screens
Transactional email delivery
What it receives: Your email address and the message we send you, and it reports back whether that message was delivered, bounced, was complained about or was delayed.
When: When we email you
Issue tracking, internal messaging and workflow tools
What it receives: Your submission, so that a person reads it and answers you: the name, company, email address, telephone number and message you entered, together with the page you submitted from, the site that referred you and your browser string. One of these is the system of record for a submission rather than a notification of it, which means a submission we cannot write there is refused rather than kept.
When: When you submit a form
Meeting scheduling and video conferencing
What it receives: Your name and email address, and the subject of the call, at the moment a person at Effect schedules the meeting and sends you the invitation. Nothing is placed in our pages by this provider any more and it therefore sets no cookies through us: the booking calendar was removed from the site on 3 September 2026 and a request for a call is now a form on our own domain.
When: When a person schedules the call you asked for, not when you browse
Website analytics
What it receives: The measurements set out in the Cookie Policy: which pages were opened, the named product steps we count, and how quickly a page rendered. Never a field you typed.
When: Analytics granted
Session recording
What it receives: A replay of your visit to the marketing website. It is not loaded inside the client workspace, and the product tree is masked.
When: Recording granted
Professional advisers, auditors and insurers
What it receives: Only what a specific engagement requires, under a duty of confidence.
When: When such an engagement requires it

There is no booking calendar on this site. Asking us for a call is a form on our own domain: what you type reaches us, we write back within one business day, and a person settles the time with you. No scheduling provider is placed in these pages, so none of them can set a cookie through us or see your address while you read. The video conferencing service receives your name, your email address and the subject of the call only when the meeting is actually created, in order to send you the invitation and the link.

We also disclose personal information where required by law, regulation or legal process, or to protect the rights, property or safety of Effect, our clients or others; and in connection with a merger, acquisition, financing or sale of assets, in which case this policy continues to apply to the information transferred until the recipient provides its own notice.

We do not sell personal information and we do not share it for cross-context behavioural advertising. We do not currently use personal information for targeted advertising.

If you would rather we did not disclose your information to the optional recipients above, the analytics, recording and embed categories, refuse the corresponding purpose on the cookie card. That refusal is available before any of them receives anything, and it takes effect immediately.

A current list of the individual providers behind these categories, with what each one does, which purpose it serves, whose cookie it is and where it processes, is published at effect.com/cookies/providers. It is linked from the consent card as well, so it is available to you before you answer rather than only after, and it is kept current without this policy being reopened.

6. International transfers

We are established in the United States and process personal information there. Where a recipient in section 5 operates in more than one country, what it handles for us may be processed outside the United States as well.

Transfers out of the European Economic Area and the United Kingdom. Where personal information about a person in the EEA or the UK is transferred to us or to a recipient outside those territories, that transfer is made under a mechanism in Chapter V of the GDPR, and under the corresponding UK provisions. In practice that means an adequacy decision where one covers the destination, and otherwise the European Commission’s Standard Contractual Clauses, with the United Kingdom International Data Transfer Agreement or the UK Addendum to those clauses for transfers from the United Kingdom, together with any supplementary measures a transfer risk assessment shows to be necessary. You may ask us for a copy of the safeguard that applies to a particular transfer at the address in section 14, and we will provide it, redacted only where commercial terms require.

Submitting information to us is not consent to an international transfer, and we do not treat it as one. Consent is a separate mechanism with its own conditions, and it cannot be inferred from the fact that somebody filled in a form. The consent you give on the cookie card is consent to an optional processing purpose. It is not the legal basis for the transfer itself, and refusing it does not leave a transfer unlawful; refusing it simply removes those recipients from the chain, so that nothing is transferred to them at all.

Transfers under Mexican law. Where Mexican law applies, the recipients in section 5 act on our instructions as encargados rather than receiving your data for their own purposes. Section 5 states the categories, what each receives and when, so that you can identify each flow before it happens.

7. How long we keep it

Where a period is fixed by our own code rather than by judgement, here it is.

The consent cookie effect-consent and the identifier effect-consent-id
How long: One year from the answer, renewed each time you answer again
The consent record on our server
How long: Three years, after which our pruning routine deletes it. That routine is run deliberately rather than on an automatic schedule, and we would rather tell you that than call it scheduled
The internal-browser mark effect-internal
How long: One year
The first-touch mark effect-ft
How long: One year. Written only if you granted analytics. It records which link first brought your browser to one of our sites, the referring host, the landing path and a random identifier. It carries nothing you typed and is sent to no third party
The record that a page was read
How long: Kept while it is useful for understanding how the site is found and read, and reviewed periodically. Without an analytics grant it carries no identifier and cannot be joined to you. We run no automatic deletion on this table today
Access and activity logs for the workspace
How long: Four hundred days, after which the same pruning routine deletes them
Enquiries, registrations and meeting records from people who never became clients
How long: Kept while the enquiry has a live purpose, reviewed periodically, and deleted at any time on request. We run no automatic deletion on this category today, and we would rather say so than publish a period nothing enforces
Client account records
How long: For the term of the agreement, and afterwards for the period tax, accounting and limitation rules require. This one is worked by review rather than by an automatic job
Copies kept in your own browser
How long: The consent answer and the internal-browser mark are also mirrored into your browser's local storage, which has no expiry of its own. Clearing site data in your browser removes them, and so does answering the cookie card again
Backups and restore copies
How long: A record deleted from our live systems can survive for a time in a backup or a restore copy. It is not returned to use, and it is deleted or overwritten on the backup cycle that applies to it
Third-party cookies
How long: The lifetimes shown in the Cookie Policy, which the vendor sets and we do not control

For anything not in this table we keep personal information for as long as the purposes in this policy require, to comply with legal obligations, resolve disputes and enforce agreements, after which we delete it or put it beyond use as De-Identified Data or Anonymous Data, as those terms are defined in our Terms of Use.

8. Security

We maintain technical and organisational measures designed to protect information against unauthorised access, loss, misuse and alteration. In concrete terms: traffic is encrypted in transit and the site is sent over HTTPS only; the sign-in session cookie is HttpOnly, Secure and SameSite-restricted, so no script can read it, and it is scoped to the workspace host alone so it is not sent to the marketing site; we hold no password in any form, because authentication is delegated to our provider; every entry to the workspace is written to an access log; and a client’s portfolio data is reachable only by the people that client’s own organisation has authorised, and, on our side, by the small number of people who administer the platform.

We hold no security certification, and we do not claim one. No method of transmission or storage is completely secure and we cannot guarantee absolute security. If a breach affecting your personal information occurs, we will notify you and the relevant authority where the applicable law requires it, within the period that law sets.

9. Personal information inside a client’s portfolio data

This section is the one that matters most to a lender, so it says plainly what happens and what does not.

A lender’s loan book contains information about that lender’s borrowers. Where such information reaches our systems, the lender decides why and how it is processed and remains responsible for it. Effect processes it solely to provide the Services, on the lender’s documented instructions and under our written agreement. In Mexican terms we act as encargado, not responsable; under the GDPR, as processor; under California law, as a service provider or contractor.

What follows from that, and each of these is a term in our client agreements rather than a statement of intent:

  • We do not use portfolio data for our own purposes. Not to train models for other clients, not to build a market database, not to enrich anything we sell to anyone else. The one exception is the narrow one our Terms of Use describe: where a client’s own agreement expressly permits it, we may create Aggregated Data or De-Identified Data as those terms are defined there. Silence in an agreement is not permission, and where the permission is absent nothing is created, nothing is owned and nothing is used.
  • Minimisation at the source. Our integrations are built to take what the analysis needs and no more. Direct identifiers of individual borrowers are not required for portfolio analytics, and where a lender’s system offers a pseudonymised export we ask for that one.
  • Reporting to a funder is aggregated. What an institution financing a lender sees is portfolio-level: arrears by cohort, concentration, covenant headroom, coverage of the data. It is reported at that level rather than as a list of borrowers, and it does not carry borrower identities.
  • The lender controls what leaves. Which fields are shared, with whom, and at what level of aggregation is the lender’s decision, recorded in the agreement.
  • We do not query credit bureaus and we hold no authorisation to do so. Where credit-bureau information exists in a lender’s own records, it arrived there under the lender’s own authorisation from its client, and it stays under the lender’s responsibility.
  • Obtaining consent is the lender’s obligation. A lender is responsible for having the legal basis and, where the law requires express written consent for financial and patrimonial data, for holding it. We require this by contract.

Pseudonymised is not anonymous. Where a lender’s export replaces a borrower’s name with a reference, the record still relates to a person who can be identified by whoever holds the key, and the lender holds it. Pseudonymisation does not make the data anonymous, and Effect continues to process such data as personal data where applicable law requires.

Three states, not one word. Our Terms of Use define Aggregated Data, De-Identified Data and Anonymous Data separately, because they are not the same thing. Data that meets the California de-identification standard is still subject to obligations; it is not anonymous in the sense the GDPR uses that word. We do not treat one as the other, we do not describe one as the other, and we do not rely on the narrower standard to justify a use governed by the wider one.

Deletion and return. On the end of an agreement, portfolio data is deleted or returned at the client’s election, and we confirm in writing when it is done. We work to a period of thirty days for our live systems. Two things that a single deletion cannot reach are stated here rather than discovered later: a copy in a backup or a restore snapshot survives until that copy is overwritten or expires on its own cycle, during which it is not returned to use; and where a law requires us to keep a record, that record is kept for the period the law sets and is used for nothing else.

If you are a borrower or applicant of one of our clients and you want to exercise a right over your information, write to that lender. It holds the relationship, the consent and the record. If you write to us instead we will pass the request on and tell you we have done so, but we cannot answer it ourselves, because acting on your data without the lender’s instruction is precisely what we have undertaken not to do.

10. Your rights, and how to use them

Write to legal@effect.com, or to Sylvent Corporation, 131 Continental Drive, Suite 301, Newark, DE 19713, United States, marked for the attention of the Data Protection contact. That address is the contact we designate for personal information and for requests about it, which is what Mexican law calls the departamento de datos personales.

Tell us four things and we can act without a second exchange: which right you are exercising; what information the request concerns; how you would like to receive our answer; and enough for us to be satisfied the request is yours. We will ask for proof of identity, and for proof of authority if you are acting for someone else. We ask for no more than that, and we do not charge for a request.

What we can actually do, said plainly. We work these requests by hand rather than through a self-service control, which changes the deadline not at all. For access and portability we provide the information you gave us and the records we hold about your use of the workspace, in a structured, commonly used and machine-readable format. For correction we change the record and tell you what changed. For deletion we delete from our live systems, tell you anything we kept and the legal reason we kept it, and section 9 explains what a deletion cannot reach. For objection, and for oposición under the ARCO rights, we stop the processing you objected to or tell you the grounds on which we do not. One thing we have not done, and would rather tell you than have you find out: we have not appointed a representative in the European Union or the United Kingdom. Requests reach us at the address above.

How long we take. Under Mexican law we answer an ARCO request within twenty business days of receiving it and, where the request is granted, give effect to it within a further fifteen business days. Under the GDPR we answer within one month, extendable by two further months for a complex request, and we tell you if we extend and why. Our acknowledgement states the date your answer is due.

In Mexico you have the ARCO rights: acceso, to know what we hold about you; rectificación, to have it corrected; cancelación, to have it removed; and oposición, to object to its use for a given purpose. You may also revoke your consent for the secondary purposes at any time, and limit the use or disclosure of your information.

In the European Economic Area and the United Kingdom you have the rights of access (art. 15), rectification (art. 16), erasure (art. 17), restriction (art. 18), portability (art. 20) and objection (art. 21), and the right to withdraw consent at any time (art. 7(3)), which for cookies is the Cookie preferences control. Withdrawal does not affect the lawfulness of what was done while consent stood. We take no decision about you by automated means that produces a legal or similarly significant effect.

If you are in California or in another United States state with a comparable law, section 11 is written for you.

11. California and other United States states

This section is the disclosure California law asks for. It is written for a resident of California, and the rights it describes are given to residents of other United States states with comparable laws on the same terms and at the same address.

The two roles again, in California’s words. For the information described in sections 2 and 5 we are a business. For personal information inside a client’s portfolio data we are a service provider, and for some engagements a contractor, processing on the client’s documented instructions under a written contract that prohibits us from retaining, using or disclosing that information for any purpose other than performing the services, from selling or sharing it, and from combining it with information from another source except as that law permits.

Categories of personal information we collect. Identifiers, including your name, business email address, telephone number, employer, account identifier and IP address; personal information described in Cal. Civ. Code section 1798.80(e), including your name and telephone number; professional or employment-related information, including your employer and your role; commercial information, meaning the products and services you enquired about and the record of a meeting you booked; and internet or other electronic network activity information, meaning the pages you viewed, the referring address, the named product steps described in the Cookie Policy, and, where you grant recording, a replay of your visit to the marketing website. Where you grant analytics, our analytics providers derive an approximate location from your IP address. We collect no biometric information, no education information and no characteristics of protected classifications, and we draw no inferences about you to create a profile.

Categories of sources. You, directly. Your device and browser. Our own systems, when you use the workspace. A client, when it authorises you to reach its data. Analytics, hosting and business-information providers, as section 2 describes.

Business and commercial purposes. Those set out in section 3: providing and maintaining the Services; creating and operating accounts and authenticating sign-ins; security, fraud prevention and detecting and repairing technical failure; answering enquiries and scheduling meetings; keeping the record of your cookie answer; meeting legal, tax and accounting obligations; and, where you grant them, the optional analytics, recording and embed purposes.

Categories of third parties and service providers we disclose to. The categories in section 5, disclosed for the business purposes listed there. We also disclose personal information where a law, regulation or legal process requires it, and in connection with a corporate transaction, as section 5 describes. We have disclosed each of those categories for a business purpose in the preceding twelve months.

Retention. The periods and criteria in section 7 apply. Where no period is fixed there, we keep each category for as long as the purpose for which it was collected requires, and then for any further period a legal, accounting or limitation rule requires, after which we delete it or put it beyond use as De-Identified Data or Anonymous Data, as those terms are defined in our Terms of Use.

Sensitive personal information. The only category of sensitive personal information we handle is the credential that lets an authorised person into the workspace. We use it to authenticate that person and to keep the account secure, and for nothing else. We do not use or disclose it to infer characteristics about anyone, which is the use that gives rise to the right to limit, and we therefore do not offer a limitation control that would have nothing to control. We do not sell or share sensitive personal information.

Do Not Sell or Share My Personal Information. We do not sell personal information and we do not share it for cross-context behavioural advertising, as California law defines those terms, and we have not done either in the preceding twelve months. We have no actual knowledge of selling or sharing the personal information of anyone under sixteen. Because there is nothing to opt out of, this website carries no “Do Not Sell or Share My Personal Information” link and honours no opt-out preference signal for a sale or share that does not occur. If that ever changes, we will publish the link and honour the signal before it does, and we will say so here first.

Your rights, and how to use them. You have the right to know what personal information we collect, use, disclose and retain about you and to receive a copy of it; to correct inaccurate personal information; to delete personal information, subject to the exceptions the statute allows; to opt out of sale and sharing, which we do not engage in; to limit the use of sensitive personal information, as described above; and not to be discriminated against or retaliated against for exercising any of them. We offer no financial incentive for personal information. Write to legal@effect.com or to the postal address in section 14. An authorised agent may make a request on your behalf with written permission from you, and we will ask you to verify that permission directly. We will confirm receipt within ten business days and answer within forty-five calendar days, extendable once by a further forty-five where the request is complex, and we will tell you if we extend and why.

12. Complaints

Bring it to us first, at the address in section 14. We would rather answer a complaint than read about it, and we will tell you what we did.

If that does not settle it: in Mexico, you may bring the matter to the federal authority that supervises data protection for private parties. In the European Economic Area and the United Kingdom, you may lodge a complaint with the supervisory authority of the country you live in, the country you work in, or the country where you believe the problem happened, and you do not have to contact us first. In the United States, California residents may contact the California Privacy Protection Agency or the Office of the Attorney General.

The Services are intended for businesses and are not directed to children under 16. We do not knowingly collect their personal information, and if we learn we have, we delete it.

Our website links to sites we do not control. Their privacy practices are governed by their own policies, not by this one.

14. Changes, and how to reach us

We may update this policy. The updated version is posted with a new “Last updated” date and, where the change is material, with additional notice. That date is recorded against your cookie answer, so a decision can always be read against the words that were on screen when you gave it.

Sylvent Corporation, 131 Continental Drive, Suite 301, Newark, DE 19713, United States.

Data protection and rights requests: legal@effect.comGeneral enquiries: info@effect.com