Invisproof Privacy Policy
Last Updated: October 7, 2026
This Privacy Policy describes how Invisproof LLC (“Invisproof,” “we,” “us,” or “our”) handles personal information that we collect through our website or through any other websites that we own or control and which link to this Privacy Policy, including when you sign in to our platform (collectively, the “Services”).
1. Who we are and how this Policy applies
Invisproof provides services that place forensic watermarks in documents, photos, video and audio and trace a file back to the marked copy it came from. We provide them to organizations (our customers), not to the general public.
Your access to the Services is facilitated through an organization (namely our customer), with which you are associated in some capacity. That organization as a controller controls your use of the Services and the personal information that is transmitted to us for processing.
In most cases, we act as a data processor (or “service provider” under some U.S. laws) for our customers, who are the data controllers (or “businesses” under some U.S. laws). In some cases, we act as a data controller. We act as data controller when we collect and process contact information and account details of our customers and prospective customers, when we collect and process information about visitors to our website, and when we process personal information for our own business purposes, such as billing, fraud prevention, and service improvements.
Our handling of personal information that may be included in content that customers upload to our platform, which we process on behalf of our customers as a service provider or processor, is governed by our agreement with our customers and by the customer’s own privacy notice. Section 2 describes that information so that you know what we hold.
2. Personal information we collect
Information you or your organization submit to us
- Account and contact information, such as your first and last name, email address, your organization and your role in it, and a profile image if you add one.
- Sign-in information, such as your password (which we keep only in hashed form), passkeys (a public key, a credential identifier and the type of device), two-step sign-in settings and backup codes, and, where your organization uses its own sign-in provider, the identifier that provider gives us.
- Purchase and transaction information. When your organization makes a purchase from us, we or our service provider(s) collect payment information. We also collect transaction information about repeated transactions. We do not receive or keep full payment card numbers; our payment provider does.
- Feedback or correspondence, such as information you provide when you contact us with questions, feedback, or otherwise correspond with us online, including through our support chat.
Automatic data collection
We and our service providers may automatically log information about you, your computer or mobile device, and your interactions over time with our Services, such as:
- Device data, such as your browser type and IP address, which we record with each sign-in session.
- Activity data, such as access times and the actions taken in an account, for example who uploaded, downloaded or checked a file and when, and changes made by administrators together with the reason they gave.
- Website analytics, such as the pages you view, the site you came from, your browser, your device type and your country. We collect these with an analytics tool that we run ourselves. It sets no cookies and does not keep your IP address.
Information we process on behalf of our customers
While providing our Services, we collect information related to the people for whom marked copies are made (“Recipients”) on behalf of our customers. When processing data on behalf of our customers, we may collect and process:
- Content: the documents, photos, video, audio and other files a customer uploads, the marked copies made from them, and the files a customer submits to be checked. These files may contain personal information.
- Recipient information: a reference the customer gives us for each person a marked copy is made for (such as an email address) and, if the customer provides it, that person’s name. We keep the reference only as a keyed pseudonym and we keep the name in a protected form.
- Records of copies: which marked copy was made for which Recipient, who in the customer’s organization requested it and when, and, when a file is checked, who submitted it, when, and which marked copy it matched.
If you are a Recipient, the customer that made a copy for you decides what information about you is given to us, in accordance with that customer’s privacy practices and policies. Invisproof does not use or access Recipients’ personal information collected by its customers through their use of the Services except with a customer’s permission, in order to provide the Services, and to provide related support and assistance.
3. How we use personal information
To operate our Services
- Provide, operate, maintain, secure and improve our Services.
- Communicate with you about our Services, including by sending you announcements, updates, security alerts, support and administrative messages, and responding to your requests, questions and feedback.
On behalf of our customers
We process personal information relating to Recipients and customer content on our customers’ behalf for the purpose of providing the Services, including to make marked copies and to tell a customer which marked copy a checked file matches, in accordance with the applicable customer contract. A match between a file and a marked copy is produced automatically; any decision based on it is made by our customer, not by us.
We do not use the personal information we process on behalf of our customers to contact you for marketing purposes nor do we sell such personal information to third parties. We do not use customer content to train models, and we do not use it for research, aggregated training or any purpose beyond delivering the contracted service.
For research and development
We may create aggregated, de-identified, or other anonymous data from personal information we collect, such as counts of files processed. We make personal information into anonymous data by removing information that makes the data personally identifiable to you. We may use this anonymous data for our lawful business purposes, including to analyze and improve our Services.
Compliance and protection
We may use personal information to:
- Comply with applicable laws, lawful requests, and legal process, such as to respond to subpoenas or requests from government authorities.
- Protect our, your or others’ rights, privacy, safety or property (including by making and defending legal claims).
- Audit our internal processes for compliance with legal and contractual requirements and internal policies.
- Enforce the terms and conditions that govern our Services.
- Prevent, identify, investigate and deter fraudulent, harmful, unauthorized, unethical or illegal activity, including cyberattacks and identity theft.
Legal basis for processing (European Economic Area and United Kingdom)
If you are in the European Economic Area or the United Kingdom, our legal basis for collecting and using the personal information described above will depend on the personal information concerned and the specific context in which we collect it. In any case, we will generally collect personal information from you only where we have your consent to do so, where we need the personal information to fulfill contractual obligations, to comply with a legal obligation or where the processing is in our legitimate interests and not overridden by your data protection interests or fundamental rights and freedoms. Where we act as a processor, our customer determines the legal basis.
4. How we disclose personal information
Service providers. We may disclose your personal information to third party companies and individuals that provide services on our behalf or help us operate our Services (such as lawyers, bankers, auditors, insurers, customer support, hosting, email hosting and delivery, and database management). They process personal information on our instructions under written contracts that require them to protect it and to use it only for our purposes. The providers used for the Services at the date of this Policy are:
| Provider | What it does for us | What it receives |
|---|---|---|
| Cloudflare, Inc. | Hosting, databases, file storage, delivery of the Services, email sending and logs | Account and sign-in information, customer files and marked copies, records of copies and Recipients |
| Modal Labs, Inc. | Computing that adds forensic watermarks to files and reads them | The file being marked or checked and the identifier of the copy; no information about Recipients. It does not keep the file after the job. |
| Backblaze, Inc. | Storage of backup copies | Backup copies of our databases |
| Stripe, Inc. | Payment processing and invoicing | Billing contact details, payment method details and the amounts paid |
| RackNerd LLC | Hosts the support chat and the website analytics that we run ourselves | Support conversations and website visit statistics |
Your organization. Information about your account and your activity in the Services is made available to the administrators of the organization through which you use the Services.
Authorities and others. We may disclose your personal information to law enforcement, government authorities, and private parties, as we believe in good faith to be necessary or appropriate for the compliance and protection purposes described above.
Business transfers. We may sell, transfer or otherwise share some or all of our business or assets, including your personal information, in connection with a business transaction (or potential business transaction) such as a corporate divestiture, merger, consolidation, acquisition, reorganization or sale of assets, or in the event of bankruptcy or dissolution. In such a case, we will make reasonable efforts to require the recipient to honor this Privacy Policy.
We do not sell personal information, and we do not share it with third parties for their own marketing.
5. Where personal information is stored and processed
Each customer organization chooses, when it is set up, whether its files and records are stored in the European Union or in the United States. That choice cannot be changed afterwards.
The choice covers the customer’s files, marked copies and records of copies and Recipients. It does not cover account and sign-in information, a directory of organization and copy identifiers and counts, numerical descriptors derived from customer photos that are used to find matching files, or the computing done by us and our service providers, which may take place in the United States and other countries.
Your personal information may therefore be transferred to, and stored and processed in, the United States, the European Economic Area or other countries, some of which do not provide equivalent protection for personal information. When transferring personal information to processors located in countries outside the European Economic Area, we rely on the EU Standard Contractual Clauses as a legal basis for transferring and processing such data.
6. How long we keep personal information
We will keep the information that we collect for as long as reasonably necessary to achieve the purpose for which you provided it, to the extent necessary for us to protect our rights, or as otherwise required by applicable laws. Our standard retention periods are:
| Personal information | How long we keep it |
|---|---|
| Account and sign-in information | For as long as your account exists in your organization. An administrator of your organization can suspend or remove an account; suspending an account does not delete information. |
| Customer files, marked copies, and records of copies and Recipients | For the length of the customer’s subscription. When the subscription ends, we keep them available to the customer for thirty (30) days and then delete them, except where longer retention is required by applicable law or necessary to resolve ongoing disputes. |
| A Recipient’s name | Until the customer erases it, which it can do at any time, or until the customer’s records are deleted. The keyed pseudonym and the record that a copy was made remain until the customer’s records are deleted. |
| Records of activity | For as long as the customer’s organization has an account with us. These records cannot be edited or removed one by one. |
| Sign-in sessions | Until they expire or you sign out. |
| Database recovery history | Up to thirty (30) days after the information is changed or deleted. |
| Purchase and transaction records | For as long as tax and accounting rules require. |
| Support conversations | For as long as needed to handle your request and any discussion that follows. |
| Website visit statistics | They do not identify you and are kept as statistics. |
7. Cookies and similar technologies
Cookies are small text files that a website stores on your device. We use only the cookies needed for the Services and our support chat to work and to keep them secure, including session handling. They are set when you sign in or use the support chat:
| Cookie | Purpose | Lifetime |
|---|---|---|
| Session | Keeps you signed in | About 7 days |
| Two-step sign-in | Holds your sign-in while you complete the second step | A few minutes |
| Trusted device | Remembers a device so that the second step is not asked again | About 30 days |
| Passkey and sign-in provider | Completes a sign-in with a passkey or with your organization’s sign-in provider | A few minutes |
| Support chat | Keeps your conversation when you return to the chat | About one year |
We do not use analytics or advertising cookies; our website analytics tool sets none. Our website does not load scripts from other companies.
Most browsers let you remove or reject cookies. To do this, follow the instructions in your browser settings. If you reject these cookies, you will not be able to sign in.
8. Security
We recognize the importance of maintaining the security of your information. We have implemented technical, administrative, and physical security measures designed to protect your information from unauthorized access, disclosure, use, and modification. These include restriction of access to personal information to people who need it, protected storage of Recipients’ names, and a rule that our own staff can see a Recipient’s name only through a recorded look-up that requires a stated reason. Please be aware though that no security measures are perfect or impenetrable.
When acting as a data processor, we will notify our customers without undue delay after becoming aware of a personal data breach. We will provide our customers with sufficient information to meet their own notification obligations and cooperate with customers in their breach response efforts.
9. Your data rights
Depending on where you live you may have certain rights with respect to your personal information, as described below. You may submit a request to exercise one or more of these rights by emailing us as provided in Section 12 (Contact) with the subject line “Privacy Rights Request” and letting us know which country or US state you live in. Once we receive a request to exercise your data privacy rights, we may be required to verify your identity before proceeding. We verify identities by comparing certain details you provide (such as name, email, and relationship) with information we have. In certain circumstances, we may decline a request to exercise the rights below, particularly where we are unable to verify your identity or locate your information in our systems, or as otherwise permitted by law.
Information we hold for a customer. In some cases, your ability to access or control your personal information may be limited by applicable law, contract, or the Services you are using. If you seek to access and control the personal information provided to us by your organization, or by a customer that made a marked copy for you, you may contact us or that organization itself (the controller). Where we hold the information as a processor, we will pass your request to that organization.
European Economic Area and United Kingdom. Data protection law gives persons in the European Economic Area and the United Kingdom certain rights with respect to their personal data. These rights include:
- The right to access: You have the right to request copies of your personal data.
- The right to rectification: You have the right to request that we correct any information you believe is inaccurate. You also have the right to request that we complete the information you believe is incomplete.
- The right to erasure: You have the right to request that we erase your personal data, under certain conditions.
- The right to restrict processing: You have the right to request that we restrict the processing of your personal data, under certain conditions.
- The right to object to processing: You have the right to object to our processing of your personal data, under certain conditions.
- The right to data portability: You have the right to request that we transfer the data that we have collected to another organization, or directly to you, under certain conditions.
If you make a request under this section, we have one month to respond to you. You also have the right to lodge a complaint with the data protection authority where you live.
California. If you live in California, you have the following rights:
- Right to Know. You can ask us to give you information about our collection and use of your personal information, including the categories of personal information we collected about you, the categories of sources from which we collected it, our purposes for collecting it, the categories of third parties to whom we disclose it, and the specific pieces of personal information we collected about you.
- Right to Delete. You can ask us to delete the personal information that we collected from you.
- Right to Correct. You can ask us to correct any inaccurate or incomplete personal information that we have about you.
We do not sell personal information and we do not share it for cross-context behavioral advertising. We will not discriminate against you for exercising the above rights. You may also have your authorized agent make a request on your behalf. If you make a request, we have forty-five (45) days to respond to you. If necessary, we may extend this period by an additional forty-five (45) days, with notice to you.
To the extent that we process any personal information relating to individuals who are California residents on behalf of a customer, we are a “Service Provider” and our customer is a “Business.” As a Service Provider, we shall not: (a) retain, use, or disclose any personal information: (i) for any purpose other than for the specific purpose of providing the Services; or (ii) outside of the direct business relationship between us and the customer; or (b) sell personal information.
Other U.S. states. Privacy laws in other states, including Colorado, Connecticut, Virginia, and Utah, give consumers certain rights with respect to their personal data. Those rights include the right to access and obtain a copy of your personal data, the right to request that we delete personal data provided by or obtained about you, and the right to correct inaccuracies in your personal data. Residents of these states can appeal a refusal to take action on a request by contacting us as provided in Section 12 (Contact).
10. Children
The Services are not intended for use by children under 18 years of age. If we learn that we have collected personal information through the Services from a child under 18 without the consent of the child’s parent or guardian as required by law, we will delete it.
11. Changes to this Privacy Policy
This Privacy Policy may be updated periodically and will be posted on the website, indicating when it was last updated. If there are material changes to our Privacy Policy, we will post a prominent notice on our website and/or provide other notice as required by law.
12. Contact
If you have any questions about this Privacy Policy or would like to exercise one or more of your data privacy rights, you can contact us by email at privacy@invisproof.com. Please note in your communication that you are making a “Privacy Inquiry.”
Invisproof LLC, 30 N Gould St Ste N, Sheridan, WY 82801, United States.