1. Introduction and Scope
Inverted Software ("Company", "we", "us", "our") is committed to protecting the privacy of individuals who visit https://www.invertedsoftware.com (the "Website") or engage our software consulting, development, artificial intelligence, outsourcing, and talent acquisition services (the "Services"). This Privacy Policy explains what personal data we collect, how we use, share, secure, and retain it, and the rights you have over it.
Our office is at 1100 Caraway Ln., Las Vegas, NV 89144, United States.
This Policy covers the Website, our marketing and sales activities, and our own business records. It does not govern data we process on behalf of a client during an engagement, which is covered by Section 2 and by the applicable client agreement.
2. Our Role: Controller and Processor
- Where we act as a controller: For Website visitors, prospects, marketing contacts, client billing contacts, job applicants, and our own business records, we determine the purposes and means of processing. This Policy governs that processing.
- Where we act as a processor or service provider: When we build, host, test, or operate systems for a client, we process personal data in that client's environment or on that client's instruction. The client is the controller. Our processing is governed by the Master Services Agreement, Statement of Work, and any Data Processing Agreement with that client, not by this Policy. We process client data only on documented instructions, do not use it for our own purposes, and do not use it to train machine learning models absent express written authorization.
- If you are an individual whose data a client provided to us: Direct your privacy request to that client. If you contact us instead, we will refer you to the client and support their response as required by our agreement with them.
3. Information We Collect
- Identifiers and Contact Data: Name, email address, phone number, company name, job title, and postal address.
- Inquiry and Engagement Content: Information you provide through contact forms, email, scheduled calls, or support requests, including any project or technical details you choose to describe.
- Commercial and Billing Data: Engagement records, contracts, purchase orders, invoices, and payment status. Card and bank details are handled by our payment processor and are not stored on our systems.
- Candidate Data: If you apply for a role with us, or if you are presented to a client through our talent acquisition Services, we may process your resume, work history, education, references, professional profiles, work authorization status, and interview notes. See Section 16.
- Usage and Device Data: IP address, browser type and version, operating system, device type, pages visited, time on page, referring URL, and date and time of access, collected automatically through server logs and analytics.
- Cookie and Similar Technology Data: Identifiers set by cookies, pixels, and similar technologies. See Section 9.
- Client Data: Data provided by or on behalf of a client during an engagement, which may contain personal data. We handle it as a processor under Section 2.
We do not collect Social Security numbers, driver's license or passport numbers, precise geolocation, biometric data, health data, or any other category defined as sensitive personal information under the California Consumer Privacy Act ("CCPA") through the Website. Do not submit that information through our contact form.
4. Notice at Collection (California)
This section is provided to California residents at or before the point of collection, as required by the CCPA as amended by the CPRA.
- Categories collected: Identifiers; customer records information (contact and billing details); commercial information (engagement and transaction records); internet or other electronic network activity information (usage and cookie data); professional or employment-related information (candidate data); and inferences drawn only for the purpose of qualifying business inquiries.
- Sources: Directly from you; automatically from your device when you use the Website; from our service providers such as hosting, analytics, and email delivery vendors; and from publicly available professional sources and referrals.
- Business purposes: The purposes listed in Section 5.
- Sensitive personal information: We do not collect it, do not use it for inferring characteristics, and therefore do not offer a "Limit the Use of My Sensitive Personal Information" option.
- Sale or sharing: We do not sell personal information and do not share it for cross-context behavioral advertising. See Section 8.
- Retention: See Section 12 for the retention period applicable to each category.
5. How We Use Your Information
- To operate, maintain, secure, and improve the Website.
- To respond to your inquiries, scope potential engagements, and prepare proposals.
- To deliver, manage, and support the Services and our client relationships.
- To process transactions and send related communications, including confirmations and invoices.
- To analyze Website usage in aggregate so we can improve content, navigation, and performance.
- To send administrative communications about updates, security notices, and support.
- To send marketing communications where permitted by law, and with your consent where consent is required. You can unsubscribe at any time using the link in any marketing email.
- To evaluate applications for employment or engagement, and to present qualified candidates to clients under a talent acquisition engagement.
- To detect, investigate, and prevent fraud, abuse, security incidents, and technical problems.
- To comply with legal, tax, accounting, audit, and regulatory obligations, and to establish, exercise, or defend legal claims.
We do not use personal data collected through the Website for any purpose materially different from those listed above without providing notice and, where required, obtaining consent.
6. Legal Bases for Processing (EEA, UK, and Switzerland)
If you are located in the European Economic Area, the United Kingdom, or Switzerland, we rely on the following legal bases:
- Performance of a contract: To deliver Services, manage engagements, and process payments.
- Legitimate interests: To respond to business inquiries, secure and improve the Website, prevent fraud, conduct business-to-business marketing, and defend legal claims. We balance these interests against your rights and you may object at any time.
- Consent: For non-essential cookies and for marketing communications where consent is legally required. You may withdraw consent at any time without affecting processing carried out before withdrawal.
- Legal obligation: To meet tax, accounting, and other statutory requirements.
7. How We Share Your Information
We share personal data only as described here:
- Service providers and processors: Vendors that perform functions on our behalf, in the following categories: website hosting and content delivery; cloud infrastructure; web analytics; email delivery and marketing; customer relationship management; scheduling and video conferencing; accounting and payment processing; source control and project management; and artificial intelligence model and inference providers. They are bound by written contracts requiring them to protect the data and use it only for the purposes we specify. A current list of the specific providers we use is available on written request.
- Personnel and subcontractors: Our employees, contractors, and subcontractors, including personnel located outside the United States, who need the data to perform their role and who are bound by confidentiality obligations. The jurisdictions involved in a given engagement are disclosed in the applicable Statement of Work or on request.
- Clients: If you are a candidate presented under a talent acquisition engagement, we share your application materials with the prospective employer.
- Legal and safety: When required by law, subpoena, or other legal process, or where we believe in good faith that disclosure is necessary to protect our rights, protect the safety of any person, investigate fraud, or respond to a lawful government request. We will notify you of a legal demand for your data unless prohibited from doing so.
- Corporate transactions: In connection with a merger, financing, acquisition, or sale of all or part of our business, subject to the acquirer honoring this Policy for data transferred.
- With your consent: For any other purpose you expressly authorize.
8. We Do Not Sell or Share Your Personal Information
We do not sell personal information for monetary or other valuable consideration, and we do not share it for cross-context behavioral advertising, as those terms are defined under the CCPA. We have not done so in the preceding twelve months.
Nevada residents: Under Nevada Revised Statutes Chapter 603A, you have the right to submit a verified request directing us not to sell any covered information we have collected about you. We do not sell covered information, but you may still submit a request to our designated address at contact@invertedsoftware.com with the subject line "Nevada Opt-Out Request." We will respond within sixty (60) days.
We do not knowingly sell or share the personal information of consumers under sixteen (16) years of age.
9. Cookies, Analytics, and Opt-Out Signals
Cookies are small files placed on your device. We use cookies and similar technologies for the following purposes:
- Strictly necessary: Required for the Website to function, including security, load balancing, and form submission. These cannot be disabled through a consent tool.
- Performance and analytics: To understand in aggregate how visitors find and use the Website so we can improve it.
- Functionality: To remember preferences such as display settings.
We do not use advertising or cross-site targeting cookies on the Website.
Where required by law, non-essential cookies are set only after you consent, and you can withdraw or change that consent at any time. You can also configure your browser to refuse or delete cookies, though some parts of the Website may not function correctly as a result.
Opt-out preference signals: We recognize the Global Privacy Control (GPC) and treat a valid GPC signal as a request to opt out of any sale or sharing of personal information associated with the browser sending it. Because we do not sell or share personal information, no change to our practices is required, but the signal is honored. We do not currently respond to browser Do Not Track signals, as no common standard for them has been adopted.
10. Data Security
We maintain administrative, technical, and physical safeguards designed to protect personal data against unauthorized access, use, alteration, disclosure, and loss. These include:
- Encryption of data in transit using current TLS, and encryption at rest for data stored in our cloud infrastructure.
- Access granted on a least-privilege, need-to-know basis, with multi-factor authentication required on administrative and production accounts.
- Separation of client environments, and use of client-controlled credentials and infrastructure where an engagement provides for it.
- Written confidentiality obligations for all personnel and subcontractors, and contractual security obligations for service providers.
- Logging and monitoring of access to production systems, and a documented incident response process.
- Periodic review of access rights, dependencies, and vendor security posture.
No method of internet transmission or electronic storage is completely secure, so we cannot guarantee absolute security. Security requirements specific to an engagement, including any certification, audit, or control requirements, are addressed in the applicable client agreement.
11. Security Incident Notification
If we become aware of a security incident affecting personal data for which we are the controller, we will notify affected individuals and any applicable regulator without undue delay and within the timeframes required by applicable law. Where we process personal data on behalf of a client, we will notify that client without undue delay and, in any event, within seventy-two (72) hours of becoming aware of the incident, and will provide the information reasonably necessary for the client to meet its own notification obligations. Incident notification terms agreed in a client agreement control where they are more specific.
12. Data Retention
We retain personal data only as long as necessary for the purposes described in this Policy. Our standard periods are:
- Inquiry and prospect records: Up to twenty-four (24) months after our last substantive contact with you, then deleted or anonymized.
- Client engagement and financial records: Seven (7) years after the end of the engagement, to satisfy tax, accounting, audit, and limitations-period requirements.
- Marketing contacts: Until you unsubscribe or ask us to delete your data. We keep a minimal suppression record indefinitely so we do not contact you again.
- Candidate records: Twelve (12) months after a hiring decision, unless you consent to a longer period so we can consider you for future roles, or a client engagement requires a different period.
- Server and security logs: Up to twelve (12) months, and longer only where needed to investigate a specific security incident.
- Analytics data: Retained in aggregate or de-identified form, with identifiers removed within fourteen (14) months.
- Client data processed as a processor: For the period specified in the applicable client agreement, and returned or deleted on termination as that agreement directs.
We may retain data longer where required by law or where necessary to establish, exercise, or defend a legal claim.
13. Artificial Intelligence and Automated Decision-Making
- We do not use personal data collected through the Website, and we do not use client data, to train, fine-tune, or otherwise improve any machine learning model, except with express written authorization.
- Where an engagement involves third-party AI model or inference providers, those providers are identified in the applicable Statement of Work, and we configure zero-retention and no-training options where the provider offers them.
- We do not make decisions producing legal or similarly significant effects about Website visitors through automated processing without human involvement. Where AI-assisted tools support candidate screening under a talent acquisition engagement, a qualified person reviews the output before any decision is made, and additional disclosures are provided where local law requires them.
- You may ask us how any AI-assisted processing affecting you works, and request human review of it, by contacting us using Section 15.
14. Your Privacy Rights
Depending on where you live, you may have some or all of the following rights over your personal data:
- Know and access: Confirm whether we process your data, and obtain a copy, including the categories collected, the sources, the purposes, and the categories of recipients.
- Correct: Have inaccurate data rectified.
- Delete: Have your data erased, subject to legal retention obligations and other permitted exceptions.
- Portability: Receive your data in a portable, machine-readable format, and have it transmitted to another controller where technically feasible.
- Opt out: Opt out of the sale or sharing of personal information, of targeted advertising, and of certain profiling. We do not engage in these activities.
- Object and restrict: Object to processing based on legitimate interests, or request restriction of processing in certain circumstances.
- Withdraw consent: Withdraw consent at any time where processing is based on consent.
- Non-discrimination: Exercise these rights without receiving different pricing, service, or quality from us.
- Complain: Lodge a complaint with your data protection authority, your state attorney general, or, in California, the California Privacy Protection Agency.
Appeals. If we decline a request, our response will explain why. Residents of states that provide an appeal right, including Virginia, Colorado, Connecticut, Texas, Oregon, and Montana, may appeal by replying to our decision with the subject line "Privacy Appeal." We will respond to an appeal within forty-five (45) days and, if the appeal is denied, will provide a method to contact the relevant state attorney general.
15. How to Submit a Request
Send your request to contact@invertedsoftware.com with the subject line "Privacy Request," or by mail to the address in Section 21. Tell us which right you are exercising and provide enough detail for us to locate your data.
- Verification: We will ask you to verify your identity, typically by confirming information already in our records. We will not use verification information for any other purpose.
- Authorized agents: An agent may submit a request on your behalf with written authorization signed by you. We may still contact you to confirm the authorization.
- Timing: We respond within forty-five (45) days, and will tell you if we need a permitted extension. There is no charge unless a request is manifestly unfounded or excessive.
- Requests about client data: If your data was provided to us by one of our clients, we will forward your request to that client, who is the controller, and support their response.
16. Job Applicants and Candidates
If you apply to work with us, or are presented to a client under a talent acquisition engagement, we process your application materials to assess your suitability, conduct interviews, check references where you authorize it, verify work authorization, and, where you are placed, administer the engagement. Our legal basis is our legitimate interest in recruiting and, where applicable, steps taken at your request before entering a contract.
We share candidate materials with the prospective employer for the role you are being considered for, and with service providers that host our recruiting and communication tools. We do not sell candidate data. We retain candidate records as described in Section 12. You have the rights described in Section 14 over your candidate data, including the right to ask us to delete your profile at any time.
17. Children's Privacy
The Website and Services are directed to businesses and are not intended for anyone under eighteen (18) years of age. We do not knowingly collect personal data from children, and we do not knowingly collect personal data from anyone under thirteen (13). If you believe a child has provided us with personal data, contact us using Section 15 and we will delete it promptly.
18. International Data Transfers
We are based in the United States, and personal data we collect is processed and stored in the United States. Our personnel and subcontractors may be located in other countries, so your data may be transferred to and maintained on systems outside your state, province, or country, where data protection laws differ from those in your jurisdiction.
Where we transfer personal data out of the EEA, the United Kingdom, or Switzerland, we rely on an appropriate safeguard, which is ordinarily the European Commission's Standard Contractual Clauses, supplemented by the UK International Data Transfer Addendum for UK transfers and by the Swiss adaptations for Swiss transfers, together with any additional technical and organizational measures the transfer requires. You may request details of the mechanism applicable to a specific transfer, and a copy of the relevant safeguards, by contacting us using Section 15.
19. Links to Other Websites
The Website may contain links to sites we do not operate. If you follow a third-party link, you leave our Website and that site's own privacy policy governs. We have no control over, and assume no responsibility for, the content or privacy practices of third-party sites.
20. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will post the revised version on this page and update the "Last Updated" date. If the changes are material, we will provide additional notice, such as by email or a notice on the Website, before they take effect. Please review this Policy periodically.
21. Contact Us
For questions about this Privacy Policy, to exercise a privacy right, or to request our current list of service providers or transfer safeguards:
- Inverted Software
- 1100 Caraway Ln., Las Vegas, NV 89144, United States
- contact@invertedsoftware.com
- +1 (818) 262-8552
For the terms governing use of the Website and Services, see our Terms of Service.