Privacy Policy

At August, we are committed to protecting your privacy. This policy describes how Credicle Corporation collects, uses, and safeguards your personal information.

1. APPLICABILITY

1.1 This Privacy Policy covers personal data collection through our websites, services, and interactions with August.

1.2 This policy distinguishes between data August controls as a data controller (governed by this policy) and Customer Data processed on behalf of customers (governed by the Platform Agreement, Data Processing Addendum, and related customer agreements).

1.3 By using our Service, you acknowledge that you have read and understood this Privacy Policy.

2. PERSONAL DATA COLLECTION

We collect personal data through the following means:

2.1 Direct Provision: Information you provide directly, including account registration details, contact information, payment information, and communications with our support team.

2.2 Automatic Collection: Data collected automatically when you use our Service, including log data, usage patterns, cookies and similar technologies, device information, and IP addresses.

2.3 Third-Party Sources: Information from security partners, marketing vendors, identity verification services, and publicly available sources.

2.4 We do not collect sensitive personal data (such as health, biometric, or genetic data) except where explicitly provided by you in connection with the Service.

3. USAGE PURPOSES

We process personal data for the following purposes:

3.1 Service Provision: To provide, maintain, and improve our Service, including processing your requests and transactions.

3.2 Billing and Payments: To process payments, send invoices, and manage your account.

3.3 Service Improvement: To analyze usage patterns and improve Service functionality and user experience.

3.4 Support: To respond to your inquiries and provide customer support.

3.5 Personalization: To customize your experience based on your preferences and usage patterns.

3.6 Marketing: To send promotional communications (with your consent where required).

3.7 Fraud Prevention: To detect and prevent fraudulent activity and protect our systems.

3.8 Legal Compliance: To comply with applicable laws, regulations, and legal processes.

4. DATA SHARING

We may share personal data with the following categories of recipients:

4.1 Affiliates: Companies within our corporate group for purposes consistent with this Privacy Policy.

4.2 Service Providers: Third-party vendors who provide services on our behalf, bound by confidentiality obligations.

4.3 Third-Party Applications: When you choose to link third-party applications to our Service.

4.4 Business Reorganization: In connection with mergers, acquisitions, or asset sales, subject to confidentiality requirements.

4.5 Legal Requirements: When required by law, legal process, or to protect our rights, property, or safety.

We do not sell your personal data to third parties.

5. SECURITY AND INTERNATIONAL TRANSFERS

5.1 Security Measures: We implement technical and organizational measures designed to protect personal data against unauthorized access, alteration, disclosure, or destruction. These measures are detailed in our Security Addendum.

5.2 International Transfers: Your personal data may be transferred to and processed in countries other than your country of residence. For transfers from the EEA, UK, or Switzerland, we rely on:

• EU-U.S. Data Privacy Framework certification

• Standard Contractual Clauses approved by the European Commission

• Adequacy decisions where applicable

• Other lawful transfer mechanisms

See our Data Transfer Addendum for additional details.

6. DATA RETENTION

6.1 We retain personal data for as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law.

6.2 Retention periods are determined by: contractual requirements, legal obligations (including tax and accounting requirements), audit needs, and legitimate business purposes.

6.3 When personal data is no longer needed, we delete or anonymize it. Anonymized data may be retained indefinitely for analytical purposes.

7. YOUR RIGHTS

Depending on your location, you may have the following rights regarding your personal data:

7.1 Access: Request access to the personal data we hold about you.

7.2 Correction: Request correction of inaccurate or incomplete personal data.

7.3 Deletion: Request deletion of your personal data, subject to legal retention requirements.

7.4 Processing Objection: Object to certain processing activities.

7.5 Portability: Request a copy of your personal data in a portable format.

7.6 Marketing Opt-Out: Opt out of marketing communications at any time.

7.7 Consent Withdrawal: Withdraw consent where processing is based on consent.

7.8 Complaints: File complaints with your local supervisory authority.

To exercise these rights, contact privacy@august.law.

8. CONTACT

For privacy inquiries, data subject requests, or questions about this Privacy Policy, contact:

August Privacy Team

Email: privacy@august.law

Credicle Corporation

San Francisco, California, United States

We will respond to your request within the timeframes required by applicable law.

Last updated: January 2026