AltitudeIQ
Contact Apply to learn more

Privacy Policy

Effective July 1, 2026

  • Introduction and Scope
  • Information We Collect
  • How We Use Information
  • Data Residency and Security
  • HIPAA and Business Associate Role
  • Data Sharing and Disclosure
  • Data Subject Rights
  • Data Retention
  • Cookies and Tracking
  • International Transfers
  • Changes to This Policy
  • Contact Us

1. Introduction and Scope

ALTITUDEIQ, INC. ("AltitudeIQ," "we," "us," or "our") is committed to protecting the privacy and security of personal information. This Privacy Policy explains how we collect, use, disclose, and protect information in connection with our enterprise software platform and related services.

Our Business Model

AltitudeIQ provides B2B SaaS enterprise software solutions through two product lines with materially different deployment models:

  • A101 (Data Quality) — AltitudeIQ deploys A101 into customer-controlled cloud environments. Azure and GCP are shipped customer deployment targets and are available today; AWS is planned but not yet a customer-facing installer target. Customer data remains within the customer environment at all times for A101. We serve enterprise customers in regulated industries, including healthcare organizations where we act as a Business Associate under the Health Insurance Portability and Accountability Act (HIPAA).
  • A29 (SAP Copilot) — AltitudeIQ operates A29 as a multi-tenant SaaS platform in AltitudeIQ's own Microsoft Azure subscription (United States regions). Customer inputs to A29 (SAP metadata, ABAP source, AI-Agent prompts and completions) transit and reside in AltitudeIQ-operated infrastructure. A29's customer beta scope is limited to non-production SAP environments processing only synthetic, anonymized, or non-personal data; this scoping is a contractual obligation reflected in the A29 Beta Terms. A29 is not offered under a Business Associate framework during customer beta and does not process PHI.

AltitudeIQ is not a system of record. Customers retain full regulatory validation responsibility for all data in their environments.

Scope of This Policy

This Privacy Policy applies to:

  • Business contact information collected for account management purposes across both product lines.
  • Technical metadata collected for security and service delivery across both product lines.
  • Our role as a Data Processor / Business Associate for A101 enterprise customers.
  • Personal data processed as an inherent product function for A29 (account and authentication data, billing metadata, transactional email delivery, LLM traces, and customer configuration data in AltitudeIQ's Azure subscription).

What This Policy Does NOT Cover

For A101, this policy does not cover Customer Data (including Protected Health Information) processed on behalf of our enterprise customers within their own cloud environments. Such data is governed by our customer agreements and remains under the customer's exclusive control. For A29, customer configuration data (SAP metadata, ABAP source, AI-Agent interactions) processed in AltitudeIQ's Azure subscription is covered by this policy. AltitudeIQ does not solicit or accept Protected Health Information through this website, info@altitudeiq.ai, or any other public channel; PHI processing occurs only within customer-controlled environments under executed Business Associate Agreements.

2. Information We Collect

We collect the minimum personal information necessary for business operations. The categories differ by product line.

2.1 Business Contact Information (both products)

  • Names and job titles of authorized contacts at customer organizations.
  • Business email addresses for account management and technical communications.

2.2 Technical and Usage Data (both products)

  • IP addresses and system logs for security monitoring and service delivery.
  • Authentication metadata including login timestamps and access patterns.

2.3 A101 Internal Operational Monitoring (Control Plane)

AltitudeIQ operates an internal monitoring service ("Control Plane") for A101 infrastructure and application health. By design, Control Plane does not receive, access, or store any Customer Data or Protected Health Information (PHI). It processes narrow operational metadata only — deployment counts, health signals, aggregate performance metrics, and application version identifiers — from A101 deployments.

2.4 A29 Personal Data Processing

Because A29 is a multi-tenant SaaS platform hosted by AltitudeIQ, we process categories of personal data as part of providing the A29 service:

  • Account and authentication data: email address, name, org membership, session tokens. Processed via Stytch (A29 cloud edition) or the customer's own OIDC identity provider (A29 enterprise edition, where AltitudeIQ does not receive credentials directly).
  • Billing data: for A29 customers on the Stripe billing path, we receive payment metadata (customer, plan, invoice status). Card data flows directly from customer browser to Stripe under PCI scope; AltitudeIQ does not receive card data. Enterprise customers on the offline-billing path do not have Stripe as a processor.
  • Transactional email delivery data: email address for magic-link authentication (Stytch), billing receipts (Stripe), and other transactional messages (Resend).
  • LLM interaction traces: prompts, completions, and tool-call records containing customer configuration data. Stored in self-hosted LangFuse in AltitudeIQ's own Azure tenant. PII masking is wired at the outbound path.
  • Customer configuration data: SAP metadata, ABAP source, AI-Agent interactions from non-production SAP environments (per A29 Beta Terms scope).

3. How We Use Information

We use the limited information we collect for:

  • Service Delivery: Providing, maintaining, and supporting our platforms (A101 and A29).
  • Account Management: Managing contracts, billing, and service updates.
  • Security: Detecting, preventing, and responding to security threats across both products.
  • AI-Agent Inference (A29 only): Customer inputs to A29 (SAP metadata, ABAP source) are transmitted to configured LLM providers (Anthropic direct today; AWS Bedrock upon cutover; Google Gemini for customers using Gemini) as an inherent product function. AltitudeIQ verifies that Anthropic's API training opt-out is enabled in the integration. Customer BYO-LLM configurations bypass AltitudeIQ's LLM sub-processor relationship entirely.

We do not use customer data to train, fine-tune, or improve AI models across customers. Tenant-isolated learning only.

4. Data Residency and Security

4.1 A101 Customer-Controlled Deployment

A101 deploys into customer-controlled cloud environments. Azure and GCP are available today; AWS is planned but not yet a customer-facing installer target. Customer data remains within the customer environment at all times for A101.

4.2 A29 AltitudeIQ-Hosted Deployment

A29 is hosted in AltitudeIQ's own Microsoft Azure subscription in United States regions. Customer data for A29 (SAP metadata, ABAP source, LLM traces, billing metadata, session data) resides in this Azure subscription. AltitudeIQ does not perform international data transfers as part of standard A29 operations. If international hosting becomes available in the future, it will be documented and customers will be notified through the sub-processor notification process.

4.3 Security Measures (both products)

We implement industry-standard security controls, including:

  • Encryption: Data is encrypted in transit (TLS 1.2 or higher) and at rest (AES-256-GCM application-layer encryption in addition to cloud-provider managed storage encryption).
  • Access Control: Multi-factor authentication (MFA) is required for administrative access to production-impacting systems. A29 cloud-edition customers may enable MFA via Stytch.
  • Monitoring: Continuous security logging and, for A101, automated alerting for system events. For A29, automated alerting is being matured as part of ongoing operational hardening.

4.4 Compliance Alignment

AltitudeIQ operates in alignment with the SOC 2 Trust Services Criteria. AltitudeIQ has completed a SOC 2 Type I examination; the report is available on request under NDA. AltitudeIQ is pursuing a SOC 2 Type II examination that includes A29. For A101, we implement the administrative, physical, and technical safeguards required by HIPAA for Business Associates.

5. HIPAA and Business Associate Role (A101 only)

When acting as a Business Associate for HIPAA Covered Entities (A101):

  • We execute formal Business Associate Agreements (BAAs).
  • Specific breach notification timelines are governed by executed Business Associate Agreements and Master Services Agreements. HIPAA regulatory notification of a breach of unsecured Protected Health Information is provided within 60 calendar days, as required by 45 CFR § 164.404.
  • We maintain a designated HIPAA Privacy & Security Officer (Dalton Wang, CCO) to oversee our compliance program.

A29 non-applicability: A29 is not offered under a Business Associate framework during customer beta and does not process PHI; HIPAA obligations do not attach to A29 during beta. A29 breach notification timelines are governed by the applicable A29 Beta Terms and Master Services Agreement.

6. Data Sharing and Disclosure

  • No Sale of Data: We do not sell, rent, or trade personal information. We do not use personal data for cross-context behavioral advertising.
  • Service Providers (Sub-processors): We share limited business contact information and, for A29 customers, additional operational data with essential providers who are contractually bound to protect it. Product-scoped sub-processor registers are maintained in our Sub-processor List:
    • A101 sub-processors: customer-selected cloud infrastructure (customer-direct relationship), Customer BYO LLM (customer-direct relationship), Google Workspace (support email), and ZeptoMail / Gmail / Microsoft 365 (A101 transactional email paths).
    • A29 sub-processors: Microsoft Azure (A29 hosting), Stytch (A29 cloud edition authentication), Resend (A29 transactional email), Stripe (A29 billing), Anthropic (direct API for A29 AI-Agent inference — active LLM path today), and Google Gemini (direct API for A29 customers using Gemini).
    • Conditional A29 sub-processor: Amazon Web Services (AWS Bedrock) — plumbed but not the active LLM path today. AWS becomes an operative sub-processor at the moment the A29 LLM routing flips to Bedrock in staging or production. Customers will be notified under our 30-day advance change notification procedure.
  • Legal Requirements: We may disclose information if required by law or to protect the safety of our users.

7. Data Subject Rights

Individuals may request access to, correction of, or deletion of their personal information by contacting us at privacy@altitudeiq.ai. Under applicable law, data subjects may exercise:

  • Right to access their personal data (GDPR Art. 15; CCPA §1798.100).
  • Right to correction (GDPR Art. 16; CCPA §1798.106).
  • Right to erasure (GDPR Art. 17; CCPA §1798.105).
  • Right to portability (GDPR Art. 20).
  • Right to object (GDPR Art. 21).
  • Right to restrict processing (GDPR Art. 18).
  • Right to withdraw consent (where consent is the legal basis).

We respond to verified requests within statutory deadlines: 45 days for CCPA (extendable once for 45 more), comparable timelines for state privacy laws (VA CDPA, CO CPA, CT DPA, UT UCPA, TX TDPSA, OR OCPA), and 30 days for GDPR/LGPD.

For A101: For requests regarding data held within a customer's A101 environment, please contact that customer organization directly.

For A29: Data subject requests regarding A29 personal data (account, authentication, billing, LLM traces, customer configuration data) may be directed to AltitudeIQ; we will respond directly consistent with the above statutory deadlines.

8. Data Retention

Data retention is governed by our Data Retention & Destruction Policy. Summary categories:

  • Business Contact Information: Retained for the duration of the business relationship plus a reasonable period not to exceed three years for legal and audit purposes.
  • Technical Logs (A101): Retained for up to 24 months unless a longer period is required for security investigations.
  • A29 Retention: A29 audit logs — a configurable floor of at least 90 days; Loki application logs — 30 days; Tempo traces — 14 days; account data — life of account plus 90 days post-closure; billing data (wallet ledger) — 7 years post-account-closure in a segregated store with a dedicated cryptographic key; conversation history and artifacts — life of account plus 90 days post-closure; platform configuration and metadata — 30 days post-termination.

9. Cookies and Tracking

  • No cross-context behavioral advertising cookies or pixels are used on AltitudeIQ properties.
  • Analytics data is limited to aggregate, de-identified metrics.
  • AltitudeIQ does not sell or share personal information as defined under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA) — see Section 6, "No Sale of Data." Because no sale or sharing occurs, a dedicated "Do Not Sell or Share My Personal Information" mechanism is not currently provided on this website.

10. International Transfers

  • A101 — Data resides in customer-selected cloud regions.
  • A29 — Data resides in United States Azure regions. Personal data is stored and processed in the US. Customers in Brazil are covered by the A29 LGPD DPA. AltitudeIQ does not perform international data transfers as part of standard A29 operations.

11. Changes to This Policy

We may update this policy periodically. Material changes will be communicated to customers via email or through official technical update channels. Changes affecting the A101 or A29 sub-processor surface follow our 30-day advance notification procedure.

12. Contact Us

Dalton Wang

Chief Compliance Officer & HIPAA Privacy Officer

ALTITUDEIQ, INC.

3801 N Capital of TX Hwy, Ste E-240, Austin, TX 78746, United States

Privacy inquiries: privacy@altitudeiq.ai · Officer: dwang@altitudeiq.ai

© 2026 AltitudeIQ, Inc. All rights reserved.
Trust Privacy Policy