Privacy Policy
This Policy explains how Innovation Media Services Inc collects, uses, discloses, stores and otherwise processes personal information in connection with InnMedia OS, our websites, software, APIs and related services.
1. Our role
For account registration, billing, website analytics, sales, support, security and our own business operations, Innovation Media Services Inc generally determines why and how personal information is processed and therefore acts as a controller, business or equivalent role under applicable law.
When an enterprise customer submits or connects personal data to InnMedia OS and instructs us to process it on the customer’s behalf, the customer generally acts as controller/business and InnMedia generally acts as processor/service provider, subject to the applicable agreement and law. In those cases, requests concerning Customer Content should ordinarily be directed to the relevant customer.
2. Information we collect
Depending on how you interact with us, we may collect and process:
- Identity and contact data: name, business email, phone number, job title, organization, country and account identifiers.
- Account and authentication data: login information, user IDs, role and permission data, authentication events and security-related records.
- Billing and transaction data: subscription details, invoices, payment status, billing address, tax information and transaction metadata. Payment card details may be processed directly by payment providers rather than stored by us.
- Customer Content: prompts, instructions, text, files, images, audio, video, URLs, source material, publishing data, workflow data, brand rules, connected-account data and other information submitted to the Services.
- Usage and device data: IP address, browser, device and operating-system information, language, approximate location derived from IP, session data, timestamps, pages, clicks, feature use, diagnostic events, logs, API activity and performance data.
- Support and communications: messages, support tickets, call or meeting information, feedback and correspondence.
- Integration data: information received from services you connect, authorize or use with InnMedia OS.
- Public and third-party data: business information, public web content, professional information and other data obtained from public sources, partners, service providers or customers where permitted by law.
Please do not submit sensitive or regulated personal data unless necessary, lawful and expressly permitted by your agreement with us.
3. Sources of information
We obtain information directly from you; from your employer or organization; from administrators and other authorized users; from connected third-party services; automatically through use of the Services; from payment, identity, security, analytics and infrastructure providers; from public sources; and from business partners where permitted.
4. How we use information
We may use personal information to:
- provide, operate, host, authenticate, maintain and support the Services;
- process content, execute workflows, publish to connected destinations and provide AI-enabled features;
- manage accounts, subscriptions, billing, credits, usage limits and customer relationships;
- monitor, troubleshoot, secure and improve performance, reliability, safety and abuse prevention;
- develop and evaluate features, products, models, workflows and services, including through aggregated or de-identified data where reasonably appropriate;
- personalize user experience, preferences and communications;
- measure website and product usage and understand feature adoption;
- respond to support, sales and other requests;
- send operational notices and, where permitted, marketing communications;
- enforce contracts and policies, protect rights and prevent fraud or misuse;
- comply with law, lawful requests, sanctions, export controls and regulatory obligations;
- establish, exercise or defend legal claims and complete audits, financing or corporate transactions.
5. Legal bases where applicable
Where laws such as the GDPR require a legal basis, we rely on one or more of the following as appropriate: performance of a contract; steps requested before entering into a contract; our legitimate interests in providing, securing, improving and operating the Services and our business; compliance with legal obligations; consent; and other lawful bases available under applicable law.
Where we rely on legitimate interests, we consider the nature of the processing, its necessity and the interests, rights and expectations of affected individuals.
6. How we disclose information
We may disclose personal information to:
- Affiliates and personnel who need access for the purposes described in this Policy.
- Cloud, hosting, infrastructure and security providers that store, transmit, secure or operate data and Services.
- AI and model providers used to process requests, generate or evaluate content, route tasks or provide specialized functionality.
- Payment, billing, analytics, communications, support and business-software providers.
- Customer-authorized integrations and publishing destinations when you direct us to exchange information with them.
- Professional advisers, auditors, insurers, financing sources and transaction counterparties subject to appropriate obligations.
- Government authorities, courts and other parties where we reasonably believe disclosure is required or appropriate to comply with law, protect rights or safety, investigate misuse or enforce agreements.
- Successors and transaction parties in connection with an actual or proposed merger, acquisition, financing, restructuring, insolvency or sale of assets.
Service providers and subprocessors may process information in multiple jurisdictions. We may change providers as our Services evolve.
7. AI systems and Customer Content
InnMedia OS may route Customer Content and related metadata through proprietary and third-party AI systems in order to perform requested functions. Depending on configuration and contractual terms, this may include research, classification, translation, generation, verification, image/audio/video processing, optimization and model routing.
When we process personal data contained in Customer Content on behalf of a customer, we process it according to the customer’s instructions, our agreement and applicable law. Customers are responsible for ensuring they have authority and a lawful basis to submit such information.
We may use de-identified or aggregated information derived from use of the Services for analytics, security, benchmarking, research and improvement. Contractual restrictions or enterprise settings may further limit use of Customer Content.
8. International data transfers and global storage
InnMedia operates using globally distributed cloud and technology providers. Personal information may be transferred to, accessed from or stored in countries other than the country where you are located, including the United States and jurisdictions that may have different data-protection laws.
Where applicable law requires safeguards for international transfers, we may rely on adequacy decisions, approved contractual clauses (including the European Commission’s Standard Contractual Clauses), transfer addenda, certifications, consent, contractual necessity or other lawful mechanisms, as applicable. We may also implement supplementary technical and organizational measures where appropriate.
9. Data retention
We retain personal information for as long as reasonably necessary for the purposes described in this Policy, including to provide the Services, maintain account and transaction records, comply with legal and tax obligations, resolve disputes, enforce agreements, protect security and maintain appropriate business records.
Retention periods vary based on data type, customer instructions, contractual commitments, legal requirements, technical backup cycles, security needs and whether information is needed for active or anticipated claims. After retention periods expire, information may be deleted, anonymized or retained in a form that no longer reasonably identifies an individual, subject to lawful exceptions and backup limitations.
10. Security
We use administrative, technical and organizational measures designed to protect information against unauthorized access, use, alteration, loss or disclosure. Measures may include access controls, authentication, logging, encryption where appropriate, network protections, provider controls, secure development practices and incident processes.
No security method is perfect. You are responsible for protecting account credentials, configuring permissions and integrations, and using the Services in a manner appropriate for the sensitivity of your data.
11. Your privacy rights
Depending on where you live and subject to legal conditions and exceptions, you may have rights to request access to personal information; correction; deletion; restriction; objection; portability; withdrawal of consent; and information about certain disclosures or international transfers. You may also have the right to complain to a data-protection authority.
We may need to verify your identity and authority before completing a request. Where we act as a processor/service provider for a customer, we may refer your request to that customer. We may retain information where permitted or required by law.
12. U.S. state privacy rights
Residents of certain U.S. states may have rights to know or access categories and specific pieces of personal information; delete or correct information; obtain portability; opt out of certain sale, sharing, targeted advertising or profiling activities; limit certain uses of sensitive information; and appeal a denied request, subject to applicable law and exceptions.
We do not sell personal information for money. Some analytics, advertising or technology disclosures may be treated as a “sale” or “sharing” under certain state laws even where no money changes hands. Where required, we honor applicable opt-out rights and recognized browser-based signals such as Global Privacy Control for covered processing.
We do not discriminate against individuals for exercising applicable privacy rights.
13. Cookies, analytics and similar technologies
We and our providers may use cookies, local storage, pixels, tags and similar technologies to operate and secure websites and Services, remember preferences, measure traffic and usage, diagnose performance and understand how users interact with our products.
Our websites may use Google Analytics and Google Tag Manager. These technologies may collect device, browser, IP, usage and interaction information and may set or read cookies subject to provider configuration and applicable law. You can use browser settings, available consent controls and supported privacy signals to manage certain technologies.
14. Children
The Services are not directed to children and are intended for business and professional users. We do not knowingly collect personal information from children in circumstances where parental consent is legally required. If you believe a child has provided personal information to us unlawfully, contact us so we can evaluate and take appropriate action.
15. Corporate transactions
Personal information may be disclosed, transferred or assigned as part of due diligence or an actual or proposed merger, acquisition, financing, reorganization, bankruptcy, receivership, sale of assets or similar transaction. Any successor may continue to process information consistent with this Policy or provide notice where required by law.
16. Changes to this Policy
We may update this Policy as our Services, providers, practices or legal requirements change. The “Effective” date above indicates the latest version. Where required, we will provide additional notice of material changes. Continued use of the Services after an updated Policy takes effect is subject to the updated Policy to the extent permitted by law.
17. Contact us
Privacy inquiries, rights requests and data-protection questions may be sent to corporate@innmediaservices.com.
Innovation Media Services Inc may request additional information reasonably necessary to verify identity, authority or the scope of a request.