Privacy Notice
Effective date: May 22, 2026
Last Updated: May 21, 2026
Accuer, Inc. (dba Playbook) (“Company”, “we”, “our”, or “us”) is committed to protecting the privacy, confidentiality, integrity, and security of personal information entrusted to us. This Privacy Notice explains how we collect, use, disclose, store, transfer, and protect personal information in connection with our websites, applications, services, products, marketing activities, customer engagements, and business operations.
This Privacy Notice has been designed to align with applicable global privacy and data protection laws, including but not limited to:
- General Data Protection Regulation (GDPR)
- UK GDPR and UK Data Protection Act
- California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA)
- Other applicable U.S. state privacy laws
- ISO 27701:2019 Privacy Information Management requirements
- SOC 2 Privacy Trust Service Criteria
- Applicable global privacy and data protection regulations
1. Scope of this Privacy Notice
This Privacy Notice applies to:
- Visitors to our websites and applications
- Customers and prospective customers
- End users of our products and services
- Business partners, suppliers, and vendors
- Individuals interacting with us through marketing, support, events, or communications
- Individuals submitting inquiries, scheduling meetings, or requesting demonstrations
- Information processed solely on behalf of our customers where we act as a processor/service provider
- Third-party websites or services not controlled by us
This Privacy Notice does not apply to:
- Information processed solely on behalf of our customers where we act as a processor/service provider
- Third-party websites or services not controlled by us
2. Roles and Responsibilities
Depending on the nature of the services provided, we may act as:
- A “Data Controller” or “Business” when we determine the purposes and means of processing personal information
- A “Data Processor” or “Service Provider” when processing personal information on behalf of our customers pursuant to contractual obligations
Where we process personal information on behalf of customers, such processing is governed by applicable contractual terms, Data Processing Agreements (“DPAs”), and customer instructions.
3. Categories of Personal Information We Collect
We may collect the following categories of personal information:
A. Identification Information
- Name
- Username or account identifier
- Company name
- Job title
- Email address
- Phone number
- Postal address
B. Technical and Usage Information
- IP address
- Browser type and version
- Device identifiers
- Operating system
- Log files
- Session information
- Usage analytics
- Cookies and tracking information
C. Professional and Business Information
- Business contact details
- Organization affiliation
- Meeting requests and communications
- Support inquiries
- Contractual information
D. Sensitive Personal Information (Where Applicable)
Depending on applicable laws and business requirements, we may process limited categories of sensitive personal information such as:
- Government-issued identifiers
- Authentication credentials
- Financial or billing information
- Precise geolocation data
We process Sensitive Personal Information only where necessary, proportionate, and legally permitted.
E. Information Collected Automatically
We may automatically collect information using cookies, analytics technologies, web beacons, and similar tracking mechanisms.
4. Sources of Personal Information
We collect personal information from the following sources:
- Directly from individuals
- Through our websites, forms, and applications
- Customer or business partner interactions
- Third-party integrations and service providers
- Cookies and analytics technologies
- Publicly available sources
- Recruitment and employment-related processes
5. Purposes of Processing Personal Information
We process personal information for the following business and operational purposes:
- Providing and managing products and services
- Managing customer relationships and support
- Scheduling meetings and responding to inquiries
- Contract management and business operations
- Identity verification and authentication
- Security monitoring and fraud prevention
- Legal and regulatory compliance
- Risk management and incident response
- Analytics, reporting, and service improvement
- Marketing and communications (where permitted)
- Managing user preferences and consent
- Protecting systems, networks, and applications
6. Legal Basis for Processing (GDPR)
Where GDPR or similar laws apply, we process personal information based on one or more of the following legal bases:
- Consent
- Performance of a contract
- Compliance with legal obligations
- Legitimate interests
- Protection of vital interests
- Public interest obligations, where applicable
Where processing is based on consent, individuals may withdraw consent at any time.
7. Data Minimization and Purpose Limitation
We collect and process only the personal information necessary for specified, explicit, and legitimate purposes. We limit the collection and use of personal information to what is relevant, proportionate, and necessary for business, contractual, legal, and operational requirements.
8. Sharing and Disclosure of Personal Information
We may disclose personal information to the following categories of recipients:
- Cloud hosting providers
- Technology and infrastructure providers
- Analytics and monitoring providers
- Customer support providers
- Professional advisors and auditors
- Regulatory authorities and law enforcement agencies
- Payment processors and financial institutions
- Business partners and affiliates
- Contractors, subprocessors, and service providers
We do not sell personal information in exchange for monetary consideration.
Where applicable under CPRA/CCPA, we do not “sell” or “share” personal information for cross-context behavioral advertising purposes.
9. Third-Party Service Providers and Subprocessors
We engage authorized third-party service providers and subprocessors to support our operations, including cloud hosting, analytics, customer support, and infrastructure services.
These providers are contractually obligated to:
- Process personal information only on our instructions
- Maintain appropriate security safeguards
- Protect confidentiality
- Comply with applicable data protection laws
A current list of significant subprocessors may be made available upon request or through a dedicated subprocessor disclosure page.
10. International Data Transfers
Personal information may be transferred to and processed in countries outside the individual’s jurisdiction of residence.
Where cross-border transfers occur, we implement appropriate safeguards, including:
- Standard Contractual Clauses (SCCs)
- Contractual safeguards
- Adequacy decisions
- Security and privacy controls aligned with applicable laws
11. Data Retention
We retain personal information only for as long as necessary to:
- Fulfill the purposes described in this Privacy Notice
- Meet legal, regulatory, contractual, and operational obligations
- Resolve disputes and enforce agreements
Retention periods are determined based on:
- Nature and sensitivity of the information
- Legal and regulatory obligations
- Business and operational requirements
- Security and audit requirements
When personal information is no longer required, we securely delete, anonymize, or dispose of the information in accordance with our retention and disposal procedures.
12. Data Security Measures
We maintain administrative, technical, organizational, and physical safeguards designed to protect personal information against unauthorized access, disclosure, alteration, loss, or destruction.
Our security measures include:
- Encryption of data in transit and at rest
- Role-based access controls
- Least privilege access principles
- Security monitoring and logging
- Vulnerability management
- Incident response processes
- Secure development practices
- Periodic risk assessments and security reviews
13. Data Accuracy and Integrity
We take reasonable steps to ensure personal information is accurate, complete, relevant, and up to date for the purposes for which it is processed.
Individuals may request correction or updates to inaccurate or incomplete personal information.
14. Privacy Risk Management and DPIAs
We maintain a risk-based privacy governance program that includes:
- Privacy impact assessments (DPIAs)
- Privacy risk assessments
- Vendor and third-party risk reviews
- Security and compliance reviews
- Periodic privacy governance evaluations
Where required by applicable law, we conduct Data Protection Impact Assessments for high-risk processing activities.
15. Incident Response and Breach Notification
We maintain incident response and breach management procedures designed to identify, investigate, contain, remediate, and respond to security and privacy incidents.
Where required by law, we will notify affected individuals and regulatory authorities within applicable legal timelines.
16. Data Subject and Consumer Rights
Depending on applicable law and jurisdiction, individuals may have the right to:
- Access personal information
- Correct inaccurate information
- Delete personal information
- Restrict or object to processing
- Withdraw consent
- Request portability of personal information
- Opt out of certain processing activities
- Limit the use of Sensitive Personal Information
- Appeal privacy decisions, where applicable
- Know categories of personal information collected
- Know categories of sources and recipients
- Opt out of sale or sharing of personal information
- Limit use and disclosure of Sensitive Personal Information
- Non-discrimination for exercising privacy rights
California Privacy Rights
California residents may also have the right to:
- Know categories of personal information collected
- Know categories of sources and recipients
- Opt out of sale or sharing of personal information
- Limit use and disclosure of Sensitive Personal Information
- Non-discrimination for exercising privacy rights
We honor applicable Global Privacy Control (“GPC”) signals where legally required.
17. Exercising Privacy Rights
Individuals may exercise their privacy rights through the following methods:
- Email: privacy@playbookteam.com
- Phone: 303-323-4296 x22
We may verify identity before fulfilling requests to protect privacy and security.
We aim to respond to requests within applicable legal timelines, including:
- GDPR: Generally within 30 days
- CPRA/CCPA: Generally within 45 days
18. Cookies and Tracking Technologies
We use cookies and similar technologies for:
- Essential website functionality
- Security and authentication
- Performance monitoring
- Analytics and usage insights
- User preferences
- Marketing and communications, where permitted
Individuals can manage cookie preferences through our cookie consent mechanisms and browser settings.
Additional information is available in our Cookie Notice.
19. Automated Decision-Making and Profiling
We do not engage in automated decision-making or profiling that produces legal or similarly significant effects unless explicitly disclosed and permitted by applicable law.
Where automated processing is used, appropriate safeguards and rights will be provided.
20. Children’s Privacy
Our services are not directed toward children under the age required by applicable law.
We do not knowingly collect personal information from children without appropriate authorization or parental consent where legally required.
If we become aware of unauthorized collection of children’s personal information, we will take appropriate steps to delete such information.
21. Vendor and Third-Party Governance
We maintain vendor management and third-party risk assessment processes designed to evaluate privacy, security, confidentiality, and regulatory compliance risks associated with service providers and subprocessors.
Appropriate contractual, security, and privacy obligations are implemented where required.
22. Privacy Governance and Accountability
We maintain an enterprise privacy governance framework supported by:
- Policies and standards
- Risk assessments and audits
- Monitoring and oversight activities
- Privacy and security training
- Continuous improvement initiatives
- Cross-functional governance involving Legal, Privacy, Security, and Compliance teams
23. Changes to this Privacy Notice
We may update this Privacy Notice periodically to reflect:
- Changes in legal or regulatory requirements
- Changes in our services or processing activities
- Security, operational, or governance improvements
Updated versions will be published with revised effective dates.
24. Contact Information
For questions, concerns, or privacy-related requests, please contact:
Privacy Office / Data Protection Team
Email: privacy@playbookteam.com
Address: PO Box 18027, Boulder, CO 80308
Phone: 303-323-4296 x22
Where required by law, individuals may also contact the relevant supervisory authority or data protection regulator.
25. Supplemental Jurisdiction-Specific Disclosures
Additional jurisdiction-specific disclosures may apply depending on an individual’s location and applicable law, including:
- European Economic Area (EEA)
- United Kingdom
- California
- Other U.S. states
- Asia-Pacific jurisdictions
Supplemental disclosures may be provided separately where required.
26. Effective Compliance Alignment
This Privacy Notice has been structured to support alignment with:
- SOC 2 Privacy Trust Service Criteria
- ISO 27001:2022 privacy-related controls
- ISO 27701:2019 Privacy Information Management requirements
- GDPR transparency and lawful basis obligations
- CCPA/CPRA transparency and consumer rights obligations
- Global privacy and cross-border transfer expectations
