Privacy Policy

PLEASE READ THIS POLICY CAREFULLY BEFORE USING OUR SERVICES
Effective Date: August 12, 2026 · Last Updated: August 12, 2026 · Version: 1.0
Sharp Archive LLC (“Sharp Archive,” “we,” “us,” “our”) provides communications archiving and AI communication review for regulated organizations. This Policy explains what we collect, why, who we share it with, and the choices you have.
BY ACCESSING, OR USING ANY PART OF OUR SERVICES, YOU AGREE TO BE BOUND BY THIS PRIVACY POLICY. IF YOU DO NOT AGREE TO ANY PART OF THIS PRIVACY POLICY, THEN YOU MAY NOT ACCESS OUR SERVICES.
This policy incorporates and includes our Terms of Service. Words and phrases not defined in this Policy shall mean the same as provided in the Terms of Service.

1. WHAT THIS POLICY COVERS

Summary: We handle two very different kinds of data — the communications we archive for our customers, and information about people who visit our website or hold an account with us. Our role, and your rights, differ between the two.

Customer archived communications. When a customer authorizes us to capture their organization’s email, messages, and posts, we act as a processor. The customer is the controller and decides what is captured and for how long. If you are an employee whose communications are archived by your employer, your employer — not Sharp Archive — is the right place to direct questions about that data.

Website visitors, account holders, and marketing contacts. For this data we act as a controller in our own right, and this Policy governs it directly.

2. INFORMATION WE COLLECT

Summary: Account details you give us, communications we archive on our customers’ instructions, business information about website visitors, and standard usage data.

2.1 Information you provide. Account data (name, email, business name, phone, business information, and payment details handled by our payment processor); support correspondence; feedback and survey responses; and anything you choose to tell our website AI assistant.

2.2 Customer communications data. When authorized by a customer, we capture communications across supported third-party platforms and process them under that customer’s instructions and service agreement.

2.3 Website visitor identification. When you visit our website we may use third-party providers to determine or infer business information about you — such as your organization, industry, role, and company size — and we record the marketing source that brought you, for example a search keyword or campaign. Identification runs first; business-information enrichment runs only where identification returns a result. We use this to tailor the page to your industry and to prepare a relevant conversation.

2.4 The AI assistant record. If you consent, we keep a per-visitor record of your conversation so we can recognize you on a return visit. It may include your organization, the questions you asked, topics discussed, your timeline, any current vendor you mention, and where you are in evaluating us.

Where our providers have identified your organization, the assistant may state company-level facts back to you — the firm name, city, or firm type — so you can confirm or correct them. It will not state facts about you as an individual that you have not told it yourself. Before relying on anything remembered from an earlier visit, it will confirm with you first.

2.5 Information collected automatically. Usage data (pages, features, errors, platforms connected), device data (IP address, device and browser, language, time zone), and cookies and similar technologies described in Section 9.

2.6 Business contact data for outreach. We obtain business contact information from third-party list providers and from a marketing agency acting on our behalf, and use it to contact businesses in the United States about our services. Every message identifies us and includes a way to opt out, which we honor.

3. AI PROCESSING

Summary: AI reviews archived communications for compliance risks, and powers the assistant on our website. It can be switched off. We do not train models on your data.

3.1 What our AI does. AI review (Alerts) analyzes archived communications to flag potential compliance risks and assist human review. The website AI assistant processes your typed conversation to respond, guide you, and — with your consent — maintain the record described in Section 2.4. AI review is the only AI feature that processes archived communications.

3.2 How it works. Content is transmitted to third-party language model providers over encrypted connections (TLS 1.2 or higher) and processed in the United States. The current providers are listed on our Sub-Processors page at https://sharparchive.com/sub-processors/.

3.3 Training data. Sharp Archive does not use archived communications, or your conversations with our AI assistant, to train, fine-tune, or improve any AI or machine-learning model. Each of our AI providers is engaged on terms addressing their own use of the content we send them; those terms are published by each provider and identified on our Sub-Processors page.

3.4 Limits. AI can be inaccurate. Statements our assistant makes about laws or regulations are general information, not legal, tax, or compliance advice. AI outputs, including Alerts, assist rather than replace human judgment, and customers remain responsible for their own compliance determinations.

3.5 Turning it off. AI review can be switched off in your settings. When it is off, none of your archived communications are sent to any language model, and core archiving continues unaffected. You can decline the AI assistant’s memory at any time and still use the website.

4. TRIALS AND DEMONSTRATIONS

Summary: If you try the product on your own data, you choose what to connect and can disconnect at any time.

We may offer a trial or a demonstration using your own data. Terms are stated at the time of the offer and may change or be withdrawn. Taking part means connecting accounts through each platform’s own authorization screen and verifying your email. You control which accounts you connect and may disconnect them at any time.

5. HOW WE USE INFORMATION

Summary: To run the service, tailor your experience, operate AI features, improve the product, market to businesses, and meet legal and security obligations.

S. No.
Purpose
Description
1.
Service delivery

Provide the website, the archive, and AI review; process transactions

2.
Personalization

Tailor the page and conversation to your industry; recognize returning visitors, with consent

3.
AI features

Operate AI review and the website assistant (Section 3)

4.
Improvement
Analyze aggregated patterns to improve the product
5.
Marketing
Send materials to businesses, with an opt-out in every message
6.
Support, legal, security
Respond to you, comply with law, prevent fraud and abuse

6. HOW WE SHARE

Summary: We share with the providers who help us run the service, with your own administrators, and where the law requires. We do not sell personal information.

We do not sell personal information. We share it with: the providers listed on our Sub-Processors page, covering cloud hosting, AI, payments, email, analytics, and visitor identification; the administrators of a customer account, for that account’s data; third-party platforms you connect; and as required by law or in connection with a business transfer. Each provider is engaged under terms addressing confidentiality and data protection.

Where processing happens. Customer archived communications and account data are processed in the United States. One website analytics provider, Hotjar, processes website usage data in Ireland. The processing location of every provider is listed on our Sub-Processors page.

Advertising. We use Google Analytics with advertising features enabled and we run advertising campaigns. This means some information about your visit is shared with Google for advertising measurement and remarketing. Under some U.S. state privacy laws this counts as “sharing” for cross-context behavioral advertising, even though we never sell personal information. To limit it, use the Global Privacy Control signal, which we honor where required, your browser’s cookie controls, or contact us at admin@sharparchive.com.

7. RETENTION

Summary: Customer data lasts as long as the relationship plus 30 days. Visitor records expire after a year of inactivity. Deletion requests are completed within 30 days.

  • Customer accounts and archived communications: retained for the duration of the relationship and per the service agreement. Retention is configurable; the default is seven years, and customers may extend it, including indefinitely. After termination, data is retained for 30 days so it can be exported, then deleted.
  • Website visitor records: deleted after one year of inactivity, measured from your last visit and reset when you return.
  • Deletion requests, and records of customers who cancel: completed within 30 days.
  • Aggregated, de-identified analytics: may be retained long-term.

Archived communications from approximately the most recent three years are held in storage optimized for immediate search and retrieval. Older communications are moved to long-term archival storage, which is equally durable but not immediate: a retrieval request is queued and fulfilled over a period set by our storage provider, typically measured in hours rather than minutes. We control how long your data is retained; we do not control how quickly an archival retrieval completes.

Legal holds may extend retention where required by law.

8. SECURITY

Summary: Encryption in transit and at rest, restricted access, and vendor review. No system is perfectly secure.

We encrypt data in transit (TLS 1.2 or higher) and at rest (AES-256), restrict access on a least-privilege basis with multi-factor authentication for administrative access, and review the security of the providers we engage. Archived communications are written to non-rewriteable, non-erasable storage, so a record cannot be altered or overwritten for the duration of its retention period. Google CASA Tier 2 has been completed.

We notify affected customers of a personal data breach without undue delay, and within 72 hours where required. No system is 100% secure, and we do not represent otherwise.

9. COOKIES AND YOUR CHOICES

Summary: A cookie banner lets you choose which optional technologies run. A separate choice controls whether our AI assistant remembers you.

We use strictly necessary, analytics, and marketing cookies and similar technologies. Our cookie banner lets you accept or decline the optional categories, and you can change your choice at any time. You can also manage cookies in your browser and through the Global Privacy Control signal, which we honor where required.

Separately, you can choose whether our AI assistant remembers your conversation between visits. If you decline, no record is kept and you can still use the website; you may opt in later. We record the date and scope of any consent you give.

You can delete your visitor record and associated personal data at any time using the link in our website footer or by contacting us. Deletion is completed within 30 days.

10. YOUR RIGHTS

Summary: Wherever you live, you can access, correct, delete, or export your data, withdraw consent, and opt out of marketing.

Regardless of jurisdiction, you may access, correct, delete, or export your data, withdraw consent, opt out of marketing, browse without being remembered, and disable AI features. To exercise any of these, use the link in our website footer or email admin@sharparchive.com.

U.S. state residents. Residents of states with comprehensive privacy laws — including California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, Iowa, Indiana, and Tennessee — have rights to know, access, delete, and correct their data, to data portability, to opt out of sale or sharing, to limit the use of sensitive information, to non-discrimination for exercising these rights, and to appeal a denied request by emailing us with “Privacy Appeal” in the subject. Authorized agents are permitted with verification.

EEA, UK, and Swiss residents. You have rights of access, rectification, erasure, restriction, portability, and objection; you may withdraw consent at any time; and you may lodge a complaint with your supervisory authority. Our lawful bases are consent, contract, legal obligation, or legitimate interests, depending on the processing. Transfers from the EEA, UK, or Switzerland rely on Standard Contractual Clauses and additional safeguards.

11. CHILDREN

Summary: Our services are for adults and organizations, not individuals under 18.

Our services are not directed to anyone under 18 and we do not knowingly collect their personal information. Where we serve education customers subject to FERPA, student information is processed at the school’s direction with Sharp Archive acting as a “school official” under that law.

12. THIRD-PARTY PLATFORMS AND APIS

Summary: We are not responsible for platforms you connect. Google and YouTube data is handled under their rules.

We are not responsible for third-party websites or for the platforms you connect to Sharp Archive. Our use of data from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements. Use of the YouTube API is subject to the YouTube Terms of Service and the Google Privacy Policy.

13. CHANGES AND CONTACT

Summary: We post changes here with a new date, and email account holders about significant ones.

Business customers subject to GDPR, UK GDPR, or comparable laws may request a Data Processing Addendum. We may update this Policy; material changes are posted with a new Last Updated date, and significant changes are emailed to account holders.

Grievance Officer and contact: Chad Gordon, Sharp Archive LLC, 6494 S Quebec St, Centennial, CO 80111 — admin@sharparchive.com