1. Scope and our privacy roles
This Privacy Policy applies to websites, applications, communications, and services operated by Round Infinity, Inc. (“Round Infinity,” “we,” “us,” or “our”), including www.roundinfinity.com and its subdomains (collectively, the “Services”). It does not apply to third-party services governed by their own privacy policies.
Round Infinity is a controller when we decide why and how to process personal data, such as website visitor, prospect, account, billing, and support data.
Round Infinity is generally a processor or service provider when a customer submits or connects data to the platform for us to process under that customer’s instructions (“Customer Data”). The customer controls that data and its privacy notice applies. If your data was submitted by a Round Infinity customer, direct your request to that customer. We will assist the customer as required by contract and law.
2. Personal data we collect
| Category | Examples |
|---|---|
| Identity and contact | Name, business email, telephone number, company, role, address, and communication preferences. |
| Account and commercial | Login identifier, organization, permissions, subscription, Order Form, transaction, billing, support, and customer relationship information. |
| Payment | Billing contact and transaction status. Payment card details are generally processed by payment providers, and we may receive limited card or payment references. |
| Device and usage | IP address, browser, device, operating system, identifiers, timestamps, pages, referring URLs, activity logs, diagnostics, and approximate location derived from IP. |
| Communications | Emails, calls, chat messages, meeting details, support requests, feedback, survey responses, and event registrations. Calls may be recorded where notice and consent requirements are satisfied. |
| Customer Data | Records, documents, contacts, messages, recordings, transcripts, prompts, Outputs, workflow events, integration data, and other content selected by a customer. |
| Security and compliance | Authentication events, audit logs, suspected fraud, abuse reports, consent records, and information needed to meet legal or contractual obligations. |
We ask customers not to submit sensitive or regulated data unless its use is expressly supported by the applicable agreement and the customer has implemented required safeguards and obtained necessary rights and consents.
3. Sources of personal data
We collect personal data directly from you; from your employer or organization; from Round Infinity customers and their users; automatically from browsers, devices, cookies, and service logs; from integrations you or a customer enables; from service providers and business partners; and from lawful public or commercial sources.
If you provide personal data about another person, you are responsible for having authority to provide it and for giving any required notice.
4. How we use personal data
We use personal data to:
- provide, configure, operate, maintain, and support the Services;
- create and administer accounts, authenticate users, process orders and payments, and manage subscriptions;
- execute customer-configured workflows, communications, integrations, and AI features;
- respond to requests, provide support, deliver service notices, and manage customer relationships;
- secure the Services, prevent fraud and abuse, investigate incidents, enforce agreements, and protect rights;
- monitor reliability, troubleshoot, analyze usage, and improve functionality and user experience;
- send marketing communications where permitted, subject to your communication choices;
- comply with law, legal process, tax, accounting, sanctions, and regulatory obligations; and
- create aggregated or de-identified information for analytics, planning, security, and service improvement, and not attempt to reidentify it except to test de-identification safeguards or as permitted by law.
We will not process personal data for a materially different purpose without providing notice or obtaining consent where required.
5. Legal bases for EEA, UK, and similar jurisdictions
Where a legal basis is required, we process personal data as necessary to perform a contract or take requested pre-contract steps; to comply with legal obligations; based on consent; and for legitimate interests that are not overridden by your rights, including operating and securing the Services, supporting customers, improving products, preventing fraud, and conducting business-to-business marketing.
You may withdraw consent at any time, but withdrawal does not affect prior lawful processing. When we process Customer Data as a processor, the customer determines the legal basis.
6. How we disclose personal data
We may disclose personal data to:
- service providers and subprocessors that provide cloud hosting, communications, analytics, security, support, payments, AI models, and other operational services under contractual restrictions;
- customer-authorized users and integrations according to account settings, permissions, workflows, and customer instructions;
- professional advisers, auditors, insurers, financing sources, and corporate advisers subject to appropriate duties;
- government authorities or other parties when reasonably necessary to comply with law, legal process, or lawful requests; enforce agreements; investigate abuse; or protect rights, safety, and security; and
- transaction participants and successors in connection with a financing, merger, acquisition, reorganization, sale of assets, insolvency, dissolution, or similar transaction, subject to applicable confidentiality and legal requirements.
We do not sell personal data for monetary consideration. As of this Policy’s effective date, we do not share personal data for cross-context behavioral advertising or process it for targeted advertising as those terms are defined by applicable US state privacy laws. If these practices change, we will update this Policy and provide legally required choices.
A current subprocessor list may be requested at support@roundinfinity.com. Third-party integrations selected by a customer may be independent controllers rather than Round Infinity subprocessors.
7. AI and automated processing
The Services may use AI to classify, summarize, extract, recommend, generate, route, or execute customer-configured work. When used with Customer Data, Round Infinity processes that data under the customer’s instructions and applicable agreement. Customers determine the purpose, configuration, permissions, review requirements, and legal basis for their use of AI features.
Round Infinity does not use website or account data to make solely automated decisions that produce legal or similarly significant effects about individuals. Customers must provide any notices, choices, human review, or appeal rights required for their own automated processing.
8. Cookies and similar technologies
We and our providers may use essential cookies, local storage, pixels, and similar technologies to maintain sessions, remember preferences, secure accounts, prevent cross-site request forgery, understand use, and improve the Services. Analytics and marketing technologies are used only as permitted by applicable law and available consent settings.
You may control cookies through browser or device settings and, where available, our consent controls. Blocking essential technologies may prevent parts of the Services from working. Where required, we recognize applicable opt-out preference signals, such as Global Privacy Control, for the browser or device sending the signal.
9. International data transfers
Round Infinity is based in the United States and may process personal data in the United States and other countries where our service providers operate. These countries may have different data protection laws.
Where required, we use recognized safeguards for restricted transfers, such as adequacy decisions, Standard Contractual Clauses, the UK International Data Transfer Addendum, or another lawful transfer mechanism. Customers may request an applicable data processing addendum by contacting us.
10. Data retention
We retain personal data only as long as reasonably necessary for the purposes described in this Policy, including providing Services, maintaining security and audit records, resolving disputes, enforcing agreements, and meeting legal, tax, accounting, and compliance requirements. Retention depends on the data category, account status, customer instructions, legal obligations, risk, and technical backup cycles.
Customer Data is retained and deleted according to the applicable agreement, customer instructions, account settings, and backup schedules. After deletion from active systems, residual copies may remain in protected backups until overwritten or deleted in the ordinary cycle. We may retain limited records where required by law or necessary for security, fraud prevention, dispute resolution, or proof of compliance.
11. Security
We maintain administrative, technical, and physical safeguards designed to protect personal data against unauthorized access, loss, misuse, alteration, and disclosure, taking account of the nature of the data and processing. Customers are responsible for configuring access controls, protecting credentials, managing endpoints and integrations, and using the Services appropriately.
No system, transmission, or security measure is completely secure. We therefore cannot guarantee absolute security. If a breach requires notification, we will notify affected customers, individuals, or authorities as required by applicable law and contractual obligations.
12. Your privacy rights
Depending on your location and subject to legal exceptions, you may have the right to confirm processing; access, correct, or delete personal data; obtain a portable copy; restrict or object to processing; withdraw consent; obtain categories of third parties receiving data; opt out of sale, targeted advertising, or certain profiling; and appeal a denied request. You will not be discriminated against for exercising applicable rights.
Submit a request or appeal to support@roundinfinity.com. Describe the right you wish to exercise and the data or account involved. We may verify your identity and authority before acting. An authorized agent may submit a request where permitted, but we may require proof of authorization and identity. We will respond within the period required by applicable law.
If Round Infinity processes your data on behalf of a customer, contact that customer first. We may refer your request to the customer.
California and other US state disclosures
The categories collected, sources, purposes, disclosures, and retention criteria are described in Sections 2 through 10. We do not offer financial incentives for personal data. We do not knowingly sell or share personal data of people under 18. Rights apply only when the relevant law applies to Round Infinity and the individual.
EEA and UK complaints
You may lodge a complaint with your local data protection authority. We encourage you to contact us first so we can try to address the concern.
13. Children
The Services are intended for business users and are not directed to children under 16. We do not knowingly collect personal data directly from children under 16 through our website or account registration. If you believe a child has provided personal data to us without appropriate authorization, contact us so we can investigate and take appropriate action.
14. Changes to this Policy
We may update this Policy to reflect changes in our Services, practices, or legal obligations. We will post the updated Policy and revise the effective date. If a change materially affects how we use personal data, we will provide additional notice or obtain consent where required by law. Prior versions may be requested from us.
15. Contact us
Round Infinity, Inc.
651 N Broad St, Suite 206
Middletown, Delaware 19709
United States
Privacy requests and questions: support@roundinfinity.com