Privacy policy
Effective date: September 15, 2026
This Privacy policy explains how Brand Action Agency, Inc., doing business as Trendjectory (“Trendjectory,” “we,” “us,” or “our”) collects, uses, discloses, retains and protects personal data. It applies when you use the Trendjectory website, application, workspaces, reports, support services and related features (together, the “Service”).
This Policy provides information about our practices under applicable privacy law. The provisions referring to the European Union General Data Protection Regulation (“GDPR”) apply where the relevant processing falls within the GDPR’s scope. Those provisions don’t mean that GDPR applies to every user or processing activity. Read this Policy with our Terms of use.
The Service is intended for business and professional use and is operated from the United States. We don’t intentionally target advertising to individuals in the EU/EEA or United Kingdom. We don’t use geographic blocking to prevent access solely because a person is located there. This Policy applies to the personal data we process, including information from website visitors, account users, and support contacts. Geographic location and acceptance of our Terms don’t waive applicable privacy rights.
1. Who controls personal data
The entity below is the controller when Trendjectory determines the purposes and means of processing. This includes its own account administration, billing, security, support, communications and legal compliance. Section 2 explains customer-controlled processing for which Trendjectory may act as a processor.
Brand Action Agency, Inc., doing business as Trendjectory
1 E. Erie St., Suite 525-2297
Chicago, IL 60611
United States
For Account deletion, use your Profile or submit a support ticket while signed in, as described in Section 9. For privacy inquiries or requests, or if you can’t access your Account, contact support@trendjectory.com. Use the subject “Privacy request” and describe your request clearly. We verify identity and relevant authority before deletion; an email alone doesn’t authorize it.
1.1 Processing related to the EU and EEA
Our commercial focus is U.S. business and professional users. We don’t intentionally target advertising to individuals in the European Union, European Economic Area, or United Kingdom, and we don’t geographically block our website or application there. Businesses in those regions that independently find the Service may register and maintain Accounts and paid subscriptions, subject to applicable law and availability.
We may receive personal information from individuals located in these regions, including through inquiries, account interactions, or information voluntarily submitted to us. We use that information for the purposes described in this Policy. A voluntary submission doesn’t waive applicable rights. We assess our obligations based on the actual activities and data processing involved; we don’t assume that all such processing is occasional.
We ask users not to submit special-category personal data, such as health information or religious beliefs, or personal data relating to criminal convictions or offences through our website, forms, or communications. If such information is received inadvertently, we’ll handle it only as permitted by applicable law and as necessary to address the request, protect our systems, or meet legal obligations. We’ll delete or minimize it where appropriate and restrict access while it is retained.
We periodically review our data practices and will update this notice and implement additional measures if the nature, scope, frequency, or risk of our processing changes. This statement doesn’t limit any privacy rights or obligations that apply by law.
2. Scope and roles
This Policy applies to personal data processed by Trendjectory when you:
- create or use an Account or Workspace;
- submit research topics, keywords, context, profiles, or other Customer Content;
- create, save, share, download, schedule, or receive reports;
- invite or collaborate with other Workspace members;
- contact support or participate in a survey;
- receive account, report, invitation, support, or service messages; or
- browse the public portions of the Service.
If an organization gives you access to a Workspace, that organization may control the Workspace and be the controller of personal data it asks Trendjectory to process. For that processing, Trendjectory acts on the organization’s documented instructions as a processor where applicable. The Data Processing Addendum in Schedule 1 of the Terms of use (“DPA”) applies where we process personal data on a customer’s behalf as a processor, service provider, or contractor under applicable data-protection law. Accepting the Terms also accepts the applicable DPA; no separate signature or email request is required. The DPA addresses instructions, confidentiality, security, subprocessors, assistance with individual rights and breaches, deletion or return, audit information, and international transfers. This Policy describes our practices and doesn’t itself replace the DPA.
For its own controller activities, Trendjectory determines the applicable purposes and legal bases. For customer-controlled processing, the customer determines those purposes and legal bases. If your request concerns a customer-controlled Workspace, you may contact that customer directly or contact us so that we can route the request and assist as required. We remain responsible for responding to requests concerning processing for which we’re the controller.
3. Personal data we collect
We collect only the data reasonably needed for the purposes described in this Policy. The categories depend on the features you use.
3.1 Account and contact data
We collect your name and email address to administer your Account and communicate with you about your subscription and use of the Service. We don’t use those account contact details for marketing. We don’t sell them or provide them to third parties for their own marketing. Service providers may process the contact details needed to operate the Service and deliver service messages, as explained in Sections 5 and 6.
The Service also creates or maintains operational account information, including Account status, email-verification status, Terms-acceptance records, password hashes, password-reset and email-verification records, identifiers, and settings needed for the features you use. Country or organization information you provide through account, Workspace, or support features is used for the relevant service purpose and applicable legal requirements. Billing addresses and payment details are handled through our payment processor as described in Section 3.5.
We don’t store your password in readable form. Passwords are transformed into a password hash for authentication. Authentication tokens and other credentials are not included in the user information returned to the application interface.
3.2 Workspace, project and research data
This may include Workspace name and settings, member roles and permissions, invitation email addresses, project names, topics, keywords, research lens, decision context, research plans, audience and geography settings, exclusions, saved profiles, schedules, collaboration settings, branding, report content, source links, evidence, recommendations, PDFs, shared-report recipients, and related identifiers.
Research and profile fields are free-text fields. Don’t include personal information about yourself or anyone else in content submitted for research, including names of individuals, personal contact details, passwords, payment details, government identifiers, health information, biometric information, or precise location information. Content entered in these fields may be sent to research providers as explained in Section 5. You may provide information needed for account administration, billing, invitations, or support through the designated features; those uses are described separately in this Policy.
3.3 Usage, security and technical data
We may collect or create IP address, browser and user-agent information, request and access timestamps, account and workspace identifiers, action history, credit and usage transactions, report and job status, error and diagnostic information, rate-limit events, and security or audit records. If you voluntarily enable support diagnostics, the support request may include basic technical context such as browser information, screen dimensions, and the page you were viewing.
3.4 Support and communications
If you contact support or reply to a support message, we may process your email address, name, ticket identifier, subject, message body, replies, status history, technical context, and related account or Workspace information. We may also process messages sent to the support mailbox, including sender and recipient addresses, subject, body, message identifiers, and attachment indicators. Don’t include passwords, access keys, full payment details, or other secrets in a support request.
3.5 Billing and payment data
Our payment processor processes payments for Trendjectory. Billing addresses, payment-card details, and other information required for payment are provided directly to our payment processor through its payment interfaces. The payment processor manages that information under its applicable terms and privacy notice, available through its payment interface. Trendjectory doesn’t receive or store full payment-card numbers, card security codes, or full bank-account details.
Our payment processor sends payment and subscription notifications to Trendjectory. We use payment status and related customer, subscription, invoice, checkout, payment, and event identifiers, plan information, billing periods, and credit records to match payments to the correct Workspace and administer access and credits. Notifications may also contain transaction amounts and billing contact information supplied to our payment processor, depending on the event. Receiving a notification is distinct from retaining its fields in our database. We use billing information for subscription administration, support, reconciliation, fraud prevention, and required financial recordkeeping. The payment processor’s handling of payment information doesn’t remove our responsibilities for information we process.
3.6 Browser storage and analytics
The application uses browser storage for authentication, Workspace selection, preferences, tutorial state, in-progress drafts, and session-related functions. Some storage lasts for a browser session; other entries remain until the application removes them or you clear them. These functional uses are separate from the analytics described below. Log out and clear browser storage when using a shared device.
We use analytics to understand visits and general use of the Service and to measure how people move from the Trendjectory marketing website to the application, register, verify an email address, and sign in. Analytics may process browser and session identifiers, predefined page categories, event timestamps, campaign or referral information, and technical information received by the analytics provider. Shared browser identifiers can connect visits across the Trendjectory website and application within the same browser. These identifiers are pseudonymous and are not necessarily anonymous.
The application is configured to send predefined page and event information rather than research inputs, report content, names, email addresses, passwords, or authentication tokens to analytics. It is also configured to disable advertising personalization and advertising user-data signals. The application honors detected analytics opt-outs, Global Privacy Control, and Do Not Track signals before loading or sending analytics. Browser blocking or clearing controls may also limit analytics, although clearing storage can sign you out or remove saved preferences.
We provide cookie consent popups and Cookie settings controls on our website and application. You can grant, refuse, change, or withdraw consent to optional cookies and analytics at any time through the relevant Cookie settings control. Your choice applies to the website or application and purposes identified in that control. Declining or withdrawing optional consent doesn’t prevent you from using otherwise available features or creating an eligible account. Withdrawal stops future optional tracking covered by your choice; it doesn’t undo processing that occurred before withdrawal.
We collect optional cookie and analytics consent through those controls, separately from account registration and acceptance of the Terms. Optional analytics remain off until you grant consent. Acceptance of the Terms or acknowledgment of this Policy is not consent to optional analytics. You may contact support@trendjectory.com with questions or to exercise applicable privacy rights. We don’t use personal data for behavioral advertising. If our tracking practices change materially, we’ll update this Policy and the relevant notices and controls.
3.7 Information from other sources
We may receive personal data from:
- a Workspace owner, administrator, inviter, or other Authorized User;
- our payment processor, through the payment and subscription notifications described above;
- an email delivery or support-mail partner, for message delivery and support operations;
- security and abuse-prevention services used to protect registration and the Service;
- public or licensed sources retrieved for a research request; and
- legal, regulatory, or professional advisers where permitted by law.
We don’t use the Service to discover named contacts or to build contact lists. Public research sources may contain incidental information about individuals. We seek to keep research focused on organizations, markets, products, topics, roles, and public business signals rather than identifiable individuals.
4. How we use personal data and our legal bases
Where GDPR applies and we act as controller, the table below describes our purposes and legal bases. Contract necessity applies only when the relevant individual is a party to the contract and the processing is necessary for that contract. For an organization’s representatives or Authorized Users, we generally rely instead on legitimate interests in the stated business activity where those interests are not overridden by the individual’s rights. Customer-controlled processing follows the customer’s lawful instructions and applicable DPA. Consent is used where required and may be withdrawn.
| Purpose | Examples of data used | GDPR legal basis |
|---|---|---|
| Create and administer an Account or Workspace | Account, contact, authentication, membership, and preference data | Performance of a contract; legitimate interests in secure account administration |
| Provide research, reports, projects, scheduling, sharing, and notifications | Research inputs, Workspace data, report data, recipient addresses, usage data | Performance of a contract; legitimate interests in delivering requested features |
| Process subscriptions, credits, invoices, refunds, and payment status | Billing metadata, Workspace and transaction records | Performance of a contract; legal obligation for accounting and financial records; legitimate interests in fraud prevention |
| Verify email, prevent abuse, protect the Service, and investigate security events | Email, IP address, user agent, timestamps, authentication records, rate-limit and audit data | Legitimate interests in security and abuse prevention; legal obligation where applicable |
| Provide support and respond to requests | Account, contact, ticket, message, and diagnostic data | Performance of a contract; legitimate interests in support and service improvement |
| Maintain reliability, troubleshoot failures, and improve the Service | Usage, error, performance, and aggregated operational data | Legitimate interests in operating and improving the Service |
| Send service and account communications | Email address, name, Workspace, report, invitation, billing, and support data | Performance of a contract; legitimate interests in service communications |
| Comply with law and protect legal rights | Relevant records, communications, billing, security, and audit data | Legal obligation; legitimate interests in establishing, exercising, or defending legal claims |
| Measure website and application use and acquisition | Browser and session identifiers, predefined page categories, events, timestamps, campaign and technical data | Consent through the cookie consent controls described in Section 3.6. Optional analytics remain off until consent is granted and stop when it is withdrawn. |
We don’t sell personal data or use personal data for behavioral advertising. We don’t use subscriber names or email addresses for marketing, or provide those contact details to third parties for their own marketing. Disclosures needed to operate the Service, carry out your instructions, or meet applicable legal requirements are described in Sections 5 and 6.
5. Research data and service providers
5.1 Research content we send
Trendjectory uses external AI, search, and data services to provide research features. We send these services the research inputs, context, report content, and supporting source material needed to process your requests. These services may use their own service providers to carry out that processing.
If personal information is included in content submitted for research, Trendjectory may transmit it to those providers as part of processing the request. This includes information about you or another person. Retrieved sources and evidence may also contain incidental personal information. We use safeguards designed to limit unnecessary disclosure, but research content is not guaranteed to be anonymized, and we don’t guarantee that all personal information will be detected, rejected, or removed before transmission.
Don’t include personal information or secrets in research topics, context fields, saved research profiles, or other content submitted for research. If we identify content that conflicts with this restriction, we may block, limit, remove, or request changes to it. This restriction doesn’t transfer or waive Trendjectory’s obligations under applicable data-protection law.
Research is focused on organizations, markets, products, topics, and public business signals. We don’t use research providers to make decisions about an identifiable individual’s employment, credit, housing, insurance, education, healthcare, or access to essential services.
5.2 Provider data practices
We use paid API accounts for production AI services, including fallback providers. We haven’t enabled optional data-sharing or model-training programs or changed the providers’ default retention settings. Those choices don’t make all providers’ practices the same. Some services prohibit training on submitted content; others permit service improvement or training for covered features under their published terms. Providers may retain content for operational, security, or legal purposes even when training is prohibited. Request-level settings, the endpoint used, and downstream routing also affect the applicable treatment.
We don’t promise that all research providers prohibit training on supplied content or provide zero data retention. We remain responsible for our obligations under this Policy and applicable law and will explain material changes to our processing as described in Section 12.
5.3 Other service partners
Personal data is also processed by service partners needed to operate the Service:
- Payment processor: collects billing addresses and full payment information through its payment interfaces and manages that information under its applicable terms and privacy notice, available through its payment interface. Trendjectory receives the payment and subscription notifications described in Section 3.5. The payment processor may act as a processor for payment services and as an independent controller for certain activities described in its notice.
- Email delivery partners: receive the minimum contact information and message content needed to send account verification, password-reset, invitation, report, support, and other requested service communications.
- Hosting, infrastructure, security and support partners: may process information to host, secure, deliver, monitor, or support the Service. The provider’s role and the applicable contractual protections depend on the processing activity.
These services have their own published contractual, privacy, and retention terms. We apply access and security controls within Trendjectory and use the partner protections applicable to the services and configurations we use. This Policy doesn’t promise that all service partners receive no personal data or retain no records.
5.4 Provider roles and subprocessor information
Where a provider processes personal data on our behalf, we require contractual protections appropriate to the processing and applicable law. Providers may act as processors for some activities and independent controllers for others. A provider’s independent purposes, including any permitted service improvement or training, require separate assessment and are not authorized merely by calling that provider a subprocessor. For customer-controlled processing, subprocessor authorization and changes are governed by the applicable DPA.
This Policy describes recipient categories and the data used for each purpose. We maintain a nonpublic register of service providers and subprocessors. To request recipient identities, relevant functions, processing locations, or safeguards under applicable privacy law or a customer DPA, email support@trendjectory.com with the subject “Provider information.” We provide the information required for the relevant request or customer relationship. We protect legitimate confidential and security-sensitive details, but don’t withhold information that applicable law requires us to provide. Customer subprocessor information and change notices are supplied privately under the DPA. Cookie settings and payment interfaces provide relevant provider notices where needed. Sections 7 and 9 explain transfer safeguards and individual requests.
6. Who receives personal data
We may disclose personal data to the following recipients only as reasonably necessary for the purposes described in this Policy:
- Workspace recipients: Workspace owners, administrators, Authorized Users, report recipients, and other people you deliberately include through collaboration or sharing.
- AI research providers and their service providers: research inputs, context, report content, and evidence needed for the requested features, including personal information if present, subject to the protections and limitations in Section 5.
- Research API, search, and source-retrieval providers: queries, keywords, source links, metadata, and related requests, which may contain personal information if included in submitted or retrieved content, as described in Section 5.
- Email delivery partners: contact addresses and the content needed to deliver requested messages.
- Payment processor: billing addresses and payment details entered through its interfaces, and the payment and subscription notifications sent to Trendjectory as described in Section 3.5.
- Analytics partners: browser and session identifiers, predefined page and event information, and related campaign and technical information used for the measurement described in Section 3.6.
- Security, hosting, storage, infrastructure, and support partners: information needed to protect, host, operate, and support the Service under appropriate safeguards.
- Professional advisers, insurers, acquirers, or successors: information needed for legal, accounting, insurance, financing, restructuring, or a corporate transaction, subject to confidentiality obligations.
- Public authorities and other recipients: where disclosure is required by law, valid legal process, or necessary to protect rights, safety, security, or the Service.
We don’t disclose personal data to third parties for their own direct marketing.
7. International transfers
Trendjectory is operated from the United States, where our production application, database, and database backups are hosted. External service providers may process data in the United States and other countries under their applicable terms and service configurations. U.S. hosting of our infrastructure doesn’t mean every AI, search, email, security, analytics, or payment-provider operation occurs only in the United States.
Where applicable law restricts an international transfer, we use the safeguards or other lawful transfer basis required for the particular data flow. When GDPR applies, a transfer outside the EEA requires a valid basis, such as an applicable adequacy decision, Standard Contractual Clauses with any necessary additional safeguards, or another legally available mechanism. A derogation is used only where its conditions are met for the specific situation. We assess relevant transfer circumstances and apply contractual, technical, and organizational safeguards appropriate to the risk.
You may request information about the mechanism relied on for a particular transfer, including a copy of applicable safeguards where required by law, by contacting support@trendjectory.com. Legitimate security or commercial redactions won’t prevent us from providing legally required information. Acceptance of this Policy alone is not consent to a restricted international transfer and doesn’t replace a required safeguard.
8. How long we keep personal data
We retain personal data only for the stated purpose and any applicable legal requirement. The periods and criteria below take account of account activity, customer instructions, transaction and dispute periods, security needs, and deletion requests. A legal hold or other exception applies only to the records and period needed for that purpose. The inactivity rules don’t require deletion of shared Workspace content still legitimately maintained for other active users.
The table below shows how long we keep each main category of data or how we determine that period:
| Data category | How long we keep it or how we decide |
|---|---|
| Active Accounts and profile data | While needed to provide and administer an active Account, including paid access and legitimate ongoing Workspace use. Unpaid Accounts follow the inactivity periods below. Closure or a valid erasure request triggers review for deletion; only records needed for a continuing lawful purpose may be retained. |
| Never-paying free Accounts | Delete after 12 months without sign-in or other authenticated use, measured from creation if the Account has never been used. We send email notice at least 30 days before scheduled deletion. Signing in before deletion restarts the inactivity period. Saved reports and other content belonging solely to the inactive Account are included, subject to shared-Workspace rights and lawful recordkeeping exceptions. |
| Former paying customers | Delete after 12 months of inactivity. The period begins no earlier than the end of paid access and the expiry or exhaustion of unexpired purchased credits; later sign-in or authenticated use restarts it. We send email notice at least 30 days before scheduled deletion. Cancellation alone doesn’t delete reports. Shared-Workspace rights and lawful recordkeeping exceptions remain applicable. |
| Workspace data and research content | While maintained for the Workspace’s requested projects, reports, research history, and related functions. Content belonging solely to an Account scheduled for inactivity deletion follows the Account periods above. Routine report deletion has a 30-day recovery period before permanent deletion from active storage. Research caches and job records are included in the applicable deletion review; formal erasure, shared-Workspace rights, backups, provider copies, and legal holds are handled separately. |
| Verification, reset and invitation records | Tokens stop authorizing access when used, expired, revoked, or replaced. Expiry of a token doesn’t itself erase the underlying record. Any continuing retention is determined by the documented authentication, abuse-prevention, and audit purpose. |
| Billing and credit records | Necessary invoices and supporting accounting records are retained for seven years from the related tax return’s filing date or due date, whichever is later. A specific audit, dispute, claim, or legal obligation may justify longer retention of relevant records. Only necessary customer and transaction identifiers are retained for this purpose; Account closure doesn’t require keeping the entire Account or its reports. Other credit and operational records require their own continuing purpose. |
| Security, audit and operational logs | Cloud application/server and HTTP request logs are retained for 30 days. Certain cloud infrastructure administrative and system audit logs have a fixed 400-day platform retention period; this doesn’t apply to every sign-in or visitor IP record. Activity and error records stored within the application database are separate and are retained only for their documented operational, security, or legal purpose. Specific investigation or claim records may be held for that matter, then deleted or anonymized when no longer needed. |
| Support communications | Routine support messages are retained while the request is open and for 12 months after resolution, then deleted. Longer retention is limited to records needed for an unresolved dispute, investigation, or applicable obligation. A valid erasure request is assessed separately; the ordinary support-history period is not an automatic exception to erasure. |
| Browser storage and analytics | Session entries generally end with the session; persistent browser entries remain until their expiry, application removal, or browser clearing. Provider-held analytics events follow the configured retention period and applicable deletion process. Clearing a browser doesn’t erase events already received by a provider. |
| Backups and recovery copies | Our production database has a rolling set of seven daily automated backups and seven days of point-in-time recovery logs. Manual database backups are automatically deleted after 30 days. Copies awaiting expiry remain outside ordinary use; restores must reapply applicable deletions. Provider-managed residual copies have separate deletion processes: Our hosting provider’s published terms allow up to 180 days for certain deletion instructions, distinct from these database backup windows. Other provider copies and justified legal holds follow their applicable arrangements. |
| Provider-held research data | Under the provider arrangement applicable to the request and feature, including any separate task, safety, audit, or legal retention. Provider retention is distinct from saved reports in Trendjectory and may require a separate deletion request. |
Using the report-delete control removes the report from ordinary use, soft-deletes related activity, and revokes its existing public share links. The stored report remains recoverable for 30 days after deletion and is then permanently deleted from active storage, unless a specific legal obligation or hold requires limited retention. Restoring a report doesn’t reactivate its old share links. A request to erase personal data is handled separately under Section 9; the recovery window doesn’t automatically postpone an erasure required by law. Backup expiry and provider-held records follow the separate criteria below. Copies already downloaded or retained by recipients may remain outside our control.
When a retention purpose ends and no applicable exception remains, the data must be deleted or irreversibly anonymized. Restricted storage is a temporary measure where a lawful retention reason still exists, not a substitute for deletion without an end point. Contact support@trendjectory.com to request applicable retention information or erasure. We’ll explain any lawful retention limitation affecting your request.
Research providers may retain request content, results, task history, or operational records under the arrangements described in Section 5. Deleting a record in Trendjectory doesn’t automatically delete every corresponding provider record. We assess the applicable correction or deletion steps and communicate them to providers where required by law or the relevant agreement. Where a provider acts independently, a separate request to that provider may be necessary; we’ll provide information and assistance required by applicable law.
9. Your privacy rights
Where GDPR applies, you may have the right to:
- obtain confirmation of whether we process your personal data and request access to it;
- correct inaccurate or incomplete data;
- request erasure of personal data in appropriate circumstances;
- request restriction of processing in appropriate circumstances;
- object to processing based on legitimate interests and to direct marketing;
- receive certain personal data in a structured, commonly used, machine-readable format and request portability;
- withdraw consent at any time where processing is based on consent, without affecting prior lawful processing; and
- lodge a complaint with a supervisory authority, particularly in the EU/EEA country where you live, work, or believe an infringement occurred.
These rights are subject to the conditions and exceptions in applicable law. We verify identity and, where relevant, an authorized representative’s authority using information reasonably necessary for the request. We may ask for proportionate additional information if we have reasonable doubts; don’t send passwords or full payment details. For customer-controlled Workspace data, we route the request to the relevant controller and assist under the applicable DPA. That routing doesn’t remove our responsibility for data we control.
To exercise a privacy right, submit a support ticket while signed in or contact support@trendjectory.com. Email remains available for people who cannot access an Account or don’t have one. Describe the right you want to exercise and provide enough information to locate the relevant data. For email, use the subject “Privacy request.” We recognize requests through other channels where applicable law requires and use proportionate verification before taking action. For GDPR requests, we respond without undue delay and within one month of receipt. Where complexity or the number of requests justifies an extension permitted by law, we may take up to two additional months, but we’ll notify you within the initial month and explain why. If we can’t act on a request, we explain the reason and available complaint or judicial remedies within the applicable period. Requests are normally free; any lawful fee or refusal for a manifestly unfounded or excessive request will be explained.
To request Account deletion, use Delete my account in your Profile when available. For assistance, submit a support ticket while signed in. We require explicit deletion confirmation and verify identity and authority over the affected Account and Workspace; we may require reauthentication or proportionate additional information. A signed-in ticket doesn’t by itself authorize deletion of a shared Workspace. If you can’t access your Account, use the email contact above for assistance and alternative verification. For ordinary self-service closure of a Workspace you own, first cancel any renewing subscription through Manage my subscription in our payment processor’s customer portal. We verify cancellation before proceeding; confirmed cancellation that stops the next renewal is sufficient even while the current paid period remains active. The Account-deletion control doesn’t automatically cancel the subscription. A member leaving another person’s Workspace doesn’t need to cancel its subscription. An owner of a shared Workspace must arrange an authorized transfer or separately confirm Workspace closure. These account-closure steps don’t prevent submission and timely assessment of a formal privacy request.
Account deletion ends access, including remaining paid-period access, and removes the Account and the Workspace content covered by the verified request from active storage. Our target is completion within seven days of verification, subject to shared-Workspace rights and justified retention exceptions. We acknowledge the request and explain completion or any limitation. Financial records, retained logs, backup expiry, and provider-managed copies follow Section 8; the seven-day target is not a promise to erase every such copy within seven days. Ordinary report-recovery and inactivity periods don’t automatically delay a required erasure. Restored systems must reapply completed deletions before affected data returns to ordinary use.
If another privacy law applies, you may request the rights available under that law using the same contact details. These may include access, correction, deletion, portability, applicable opt-outs, an authorized-agent request, or an appeal of our response. We’ll apply the relevant conditions, deadlines, and appeal process and won’t discriminate against you for exercising a protected right. We don’t use your account name or email address for marketing. Necessary account, subscription, security, support, and other service communications are handled separately from optional cookie and analytics consent.
10. How we protect personal data
We use technical and organizational measures appropriate to the nature and risk of the processing. Depending on the feature, these measures include password hashing, encrypted or hashed invitation-token handling, authentication and authorization controls, Workspace role permissions, rate limiting, input validation, secure secret management, audit logging, restricted administrative access, error-handling controls, and provider contracts or configuration intended to protect Customer Content.
We use controls designed to limit sensitive content in operational and diagnostic logs while retaining information needed to troubleshoot failures and investigate security events. These controls don’t guarantee that all research content sent to external providers is free of personal information.
No transmission, storage system, or service is completely secure. You’re responsible for using strong, unique credentials, limiting Workspace permissions, reviewing report-share recipients, logging out of shared devices, and not placing secrets or sensitive personal data in free-text fields.
If we become aware of a personal-data breach, we’ll assess and respond to it and notify regulators and affected people when required by applicable law. When acting as a processor, we’ll notify the relevant customer without undue delay and provide assistance required by law and the applicable DPA.
11. Children’s privacy
The Service is not directed to children and is intended for business and professional users. We don’t knowingly collect personal data from children in violation of applicable law. If you believe a child has provided personal data, contact support@trendjectory.com.
12. Changes to this policy
We may update this Policy when the Service, law, processing activities, providers, or safeguards change. We’ll post the revised version and its effective date and provide additional notice of material changes where required. Where a new use or disclosure requires consent, we’ll obtain that consent before the affected processing begins. Continued use of the Service alone doesn’t replace legally required consent or authorize a retroactive use inconsistent with an applicable privacy commitment.
13. How to raise a privacy complaint
Where GDPR applies, you may lodge a complaint with the supervisory authority in the EU/EEA country where you live, work, or believe the processing infringed your rights. A directory of European supervisory authorities is available through the European Data Protection Board. You don’t need to contact us first to exercise that right.
14. Contact us
For privacy questions, rights requests under applicable law, provider or transfer information, or data-removal requests:
Trendjectory privacy contact
Brand Action Agency, Inc., doing business as Trendjectory
1 E. Erie St., Suite 525-2297, Chicago, IL 60611, United States
support@trendjectory.com