Privacy Policy
Last updated: May 6, 2026
Commun-ET, LLC ("Commun-ET", "we", "us", "our") is committed to protecting your privacy and handling personal information responsibly. This Privacy Policy ("Policy") describes how we collect, use, disclose, retain, and safeguard information through commun-et.com and any subdomains (the "Site"), the PermitPilot™ platform (the "Platform"), our concierge chat, contact and quote forms, email communications, events, and other interactions with us (collectively, the "Services").
This Policy applies to personal information of website visitors, prospective customers, authorized users of the Platform, business contacts, job applicants, and other individuals who interact with us. It does not apply to data we process strictly as a service provider / processor on behalf of a customer ("Customer Data"), which is governed by the applicable Master Services Agreement (MSA) and Data Processing Addendum (DPA) with that customer.
1. Roles and scope
- Controller: For information collected through the Site, marketing, recruiting, and our own business operations, Commun-ET acts as the data controller (or "business" under U.S. state laws).
- Processor / service provider: When we host or process Customer Data inside the Platform on a customer's instructions, the customer is the controller and Commun-ET is the processor / service provider. Individuals with questions about Customer Data should contact the relevant customer (data controller) first.
2. Information we collect
2.1 Information you provide
- Identifiers and contact details: name, work email, phone, company, job title, mailing address.
- Project / inquiry details: jurisdiction, project type, timelines, budget signals, and free-text messages submitted via contact, quote, demo, or concierge chat forms.
- Account credentials (Platform): email, hashed password, SSO identifiers, multi-factor authentication factors, role, organization, and user preferences.
- Communications: messages, attachments, voicemail, and meeting notes you send to us, plus our responses.
- Payment / billing: billing contact, billing address, purchase order references; card data is processed directly by our PCI-DSS compliant payment processor, we do not store full card numbers.
- Recruiting: resume, work history, references, right-to-work information, and other materials you submit when applying for a role.
2.2 Information collected automatically
- Device and log data: IP address, user agent, device type, operating system, browser language, referring/exit URLs, timestamps, and pages or screens viewed.
- Cookies and similar technologies: see our Cookie Policy for the specific categories, vendors, retention, and how to change your choices.
- Analytics: aggregate usage via Google Analytics 4 (only after opt-in) and a privacy-friendly cookieless fallback (e.g., Plausible) when analytics consent is denied. The cookieless fallback records only aggregate page counts and does not set identifiers.
- Security telemetry: authentication events, error logs, and request metadata used to detect abuse and protect the Services.
2.3 Information from third parties
- Business contact enrichment: publicly available professional information (e.g., LinkedIn, company websites) used to qualify inbound leads.
- Identity providers: if you sign in via SSO (e.g., Google, Microsoft), we receive basic profile fields (name, email, organization, profile image) per your IdP's settings.
- Referrals and partners: contact details shared by referring partners with a stated lawful basis.
2.4 Sensitive information
We do not request, and ask that you do not submit, special categories of personal data (health, biometric, racial/ethnic origin, religious beliefs, precise geolocation, government ID numbers, financial account credentials) through the Site or chat. If you submit such data voluntarily, you consent to our processing it for the purpose for which you submitted it.
3. How and why we use information (purposes & legal bases)
Where GDPR / UK GDPR applies, our legal bases are noted in brackets.
- Provide and operate the Services, including authentication, account management, and concierge handoff to our team via Slack and email. [Contract; Legitimate interests]
- Respond to inquiries, quotes, and support requests. [Contract; Legitimate interests]
- Marketing and events, newsletters, product updates, webinars, and tailored outreach. You may opt out at any time. [Consent (where required); Legitimate interests]
- Analytics and product improvement, measure usage, improve UX, prioritize features. [Consent for non-essential cookies; Legitimate interests for aggregate, cookieless analytics]
- Security, fraud prevention, and abuse detection. [Legitimate interests; Legal obligation]
- Compliance with legal obligations, tax, accounting, export controls, lawful requests. [Legal obligation]
- Recruiting and HR. [Pre-contractual measures; Legitimate interests; Consent where required]
- Corporate transactions, diligence, financing, merger, acquisition, or asset sale. [Legitimate interests]
We do not use personal information for automated decision-making that produces legal or similarly significant effects without human review. AI-assisted features (e.g., concierge chat, lead qualification, RFI drafting) generate suggestions that are reviewed by Commun-ET personnel or platform users before action is taken.
4. Cookies and tracking technologies
We use strictly necessary cookies to operate the Site, and optional analytics cookies only after you opt in via the consent banner. See the Cookie Policy for the full list, vendors, and controls. You can change your choice at any time from the banner or the controls on the Cookie Policy page.
5. How we share information
We share personal information only as described below. We do not sell personal information for money.
- Service providers (processors): hosting and database (Supabase / Lovable Cloud), email delivery, error monitoring (e.g., Sentry), analytics, customer support, payment processing, and team collaboration tools (e.g., Slack). Each is bound by written terms and confidentiality and security obligations.
- Affiliates: Commun-ET corporate affiliates, under terms consistent with this Policy.
- Customers: if you interact with us as a user of a customer's PermitPilot tenant, your activity is visible to that customer's authorized administrators.
- Professional advisors: lawyers, auditors, insurers, and accountants under confidentiality.
- Legal and safety: to comply with law, legal process, or government requests; to enforce our terms; or to protect the rights, property, or safety of Commun-ET, our users, or others.
- Business transfers: in connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets.
- With your consent: any other sharing you direct or authorize.
"Sale" / "share" under U.S. state laws: we do not sell personal information for monetary consideration. Some analytics or advertising cookies, if you enable them, may qualify as a "sale" or "share" for cross-context behavioral advertising under California and similar state laws. You can opt out via our cookie banner or by enabling Global Privacy Control (GPC) in your browser, which we honor as a valid opt-out.
6. International data transfers
Commun-ET is based in the United States. Personal information may be processed in the U.S. and other jurisdictions where we or our service providers operate. When we transfer personal information from the EEA, UK, or Switzerland to a country that has not received an adequacy decision, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum, and supplementary technical and organizational measures. A copy of the relevant safeguards is available on request.
7. Data retention
We retain personal information only for as long as necessary to fulfill the purposes for which it was collected, including legal, tax, accounting, or reporting obligations, and to resolve disputes and enforce agreements. Typical retention windows:
- Marketing leads / inquiries: up to 24 months from last interaction, then deletion or anonymization.
- Platform account data: for the term of the customer agreement plus 30-90 days for offboarding, then deletion per the DPA.
- Server and security logs: typically 30-365 days, depending on the system.
- Billing and tax records: minimum 7 years where required by law.
- Recruiting records: up to 24 months unless a longer period is permitted with your consent.
8. Security
We maintain administrative, technical, and physical safeguards designed to protect personal information, including encryption in transit (TLS 1.2+) and at rest, role-based access control, least-privilege provisioning, mandatory MFA for production access, code review, vulnerability scanning, audit logging, and an incident response process. No system is perfectly secure; please notify us promptly at security@commun-et.com of suspected incidents. Where required by law, we will notify affected individuals and regulators of qualifying data breaches.
9. Your rights and choices
Depending on your location, you may have the following rights:
- Access, request a copy of the personal information we hold about you.
- Correction, ask us to correct inaccurate or incomplete information.
- Deletion, ask us to delete your personal information, subject to exceptions.
- Portability, receive your information in a structured, machine-readable format.
- Restriction / objection, restrict or object to certain processing, including direct marketing and processing based on legitimate interests.
- Withdraw consent, where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing.
- Opt out of sale/share/targeted advertising, via our cookie banner or by enabling Global Privacy Control.
- Non-discrimination, we will not discriminate against you for exercising any of these rights.
- Lodge a complaint, with your local supervisory authority (e.g., your EU Data Protection Authority, the UK ICO, or your U.S. state Attorney General).
To exercise any of these rights, email privacy@commun-et.com with the subject line "Privacy Rights Request." We will verify your identity (typically by confirming control of the email address on file or, for Platform users, via your account) and respond within the timeframes required by applicable law (generally 30-45 days). You may use an authorized agent; we will require written authorization and verification.
9.1 Region-specific disclosures
California (CCPA / CPRA): in the past 12 months we have collected the categories of personal information described in Section 2 (identifiers, commercial information, internet/network activity, professional/employment information, inferences) for the business purposes described in Section 3, and disclosed them to the categories of recipients in Section 5. We do not knowingly sell or share the personal information of consumers under 16. California residents have the right to limit the use of sensitive personal information; we do not use sensitive personal information beyond purposes permitted without a right to limit.
EEA / UK / Switzerland: our legal bases are listed in Section 3. Our EU/UK representative can be appointed on request, contact privacy@commun-et.com.
Other U.S. states (e.g., Colorado, Connecticut, Virginia, Utah, Texas, Oregon): you have similar rights of access, correction, deletion, portability, and opt-out of targeted advertising / sale / profiling, exercisable through the contact above.
10. Children's privacy
The Site and Platform are intended for business users and are not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.
11. Third-party links and integrations
The Site and Platform may link to or integrate with third-party services (e.g., Mapbox, Google, Slack, identity providers). Their processing is governed by their own privacy policies, which we encourage you to review.
12. Do Not Track and Global Privacy Control
Most browsers offer a "Do Not Track" (DNT) signal. Because there is no consensus standard, we do not respond to DNT. We do honor Global Privacy Control (GPC) signals as a valid opt-out of "sale" or "sharing" of personal information where required by law.
13. Changes to this Policy
We may update this Policy from time to time. Material changes will be highlighted on this page with a revised "Last updated" date and, where appropriate, additional notice (e.g., email or in-product). Your continued use of the Services after the effective date constitutes acceptance of the updated Policy.
14. Contact us
Commun-ET, LLC
Attn: Privacy Office
Email: privacy@commun-et.com
Security: security@commun-et.com
Legal: legal@commun-et.com
