Privacy Policy
Civentry, a product of Daddisyn Labs, LLC, Moorpark, California
Effective date: June 17, 2026
Last updated: June 17, 2026
1. Overview
This Privacy Policy explains what information Civentry ("Civentry," "we," "us," "our") collects, how we use and protect it, and the choices you have. Civentry provides software for community associations (HOAs) and the firms that manage them to organize financial documents, generate AI-assisted summaries, control resident transparency, and manage vendor bids. We handle sensitive financial documents and treat that responsibility seriously.
This policy is written with the California Consumer Privacy Act (CCPA), as amended by the CPRA, and the other U.S. state consumer privacy laws in mind, and we honor the rights described below to the extent those laws apply to us. These laws generally apply to a business only once it meets certain thresholds (for example, annual gross revenue over a statutory amount, processing the personal information of a large number of state residents per year, or deriving a defined share of revenue from selling or sharing personal information). We may not currently meet these thresholds in every state, but we follow privacy practices aligned with them as a matter of trust and forward-readiness.
State-specific rights, the states whose laws apply, sensitive-data consent, universal opt-out signals, and appeal procedures are set out in Section 18 (U.S. State Privacy Rights) below.
2. Our Two Roles: When We Are a "Business/Controller" and When We Are a "Service Provider/Processor"
Civentry interacts with personal information in two distinct capacities, and your rights and our obligations depend on which one applies.
As a business / controller, your account and use of Civentry. When you create an account and use the Service, we determine how your account, billing, and usage information is handled. For that information, Civentry is the "business" (CCPA) or "controller" (other state laws). This Privacy Policy governs that information directly.
As a service provider / processor, the documents and data your Organization uploads. When an Organization (an HOA, or a management firm acting for one or more HOAs) uploads documents and data to Civentry, including financial reports and any resident personal information contained in them, the Organization decides what to upload and why. For that information, the Organization is the "business"/"controller" and Civentry acts as the Organization's "service provider"/"processor." We process that information only to provide the Service to the Organization, under the Organization's instructions and our agreement with the Organization (including any Data Processing Agreement). We do not sell it, we do not use it for our own independent purposes, and we do not combine it with personal information from other sources except as permitted by that agreement and applicable law.
If you are a resident of a community association and your information appears in documents your HOA uploaded, please read Section 9 (Residents and Other Individuals Whose Data an Organization Uploads), which explains who controls that information and how to exercise your rights.
3. Information We Collect
Account information. Name, email address, and role within your Organization.
Organization information. Organization name, address, unit count, and management type (self-managed or professionally managed). For management firms, this may include the firm's identity and the associations it administers.
Documents you upload. Financial reports, budgets, reserve studies, bank statements, vendor invoices, delinquency reports, governing documents, and similar files. These may contain personal information about residents that the Organization chooses to upload.
Data derived from documents. Structured financial data extracted from uploads by automated and AI processing.
Resident information (if an Organization uploads or enters it). Resident names, email addresses, and access links used to share board-approved, resident-safe summaries.
Usage data. Login events, feature usage, session data, and audit logs generated as you use the Service.
Payment information. Handled entirely by our payment processor, Stripe. We do not collect or store your full payment card or bank account numbers.
Notice at collection (California). At or before the point of collection, this Policy serves as notice to California residents of the categories of personal information we collect (described in this Section 3), the purposes for which we use them (Section 5), the fact that we do not sell or share personal information for advertising (see Sections 8 and 15), and how long we retain personal information (Section 10). We do not collect the sensitive categories listed in Section 4.
4. Information We Do Not Collect
To be clear about our boundaries, Civentry does not collect:
- individual homeowner payment history beyond what appears in documents an Organization uploads;
- Social Security numbers or other government identifiers;
- full credit card or bank account numbers (these are handled by Stripe);
- medical or health information.
5. How We Use Information
We use information to:
- provide, operate, and maintain the Service;
- process uploaded documents and generate AI-assisted summaries, talking points, and analyses for the Organization's review and approval;
- enforce role-based access and tenant isolation;
- process subscriptions and billing (via Stripe);
- communicate with you (transactional emails, security alerts, support);
- maintain audit logs and meet security, compliance, and legal obligations;
- develop, maintain, secure, and improve the Service, using aggregated or de-identified usage and performance information for this purpose, in accordance with Section 7.
We do not use the contents of uploaded financial documents for advertising, and we do not sell or use that uploaded content for our own independent purposes. We use privacy-focused, first-party analytics to understand how our marketing site is used (see Section 15). We do not use third-party advertising or retargeting pixels, and we do not sell or share personal information for cross-context behavioral advertising or targeted advertising. We do not use the contents of one Organization's uploaded documents to expose, display, or provide identifiable information to another Organization.
When we act as a service provider/processor (Section 2), we use uploaded documents and resident information only to provide the Service to the Organization and as permitted by our agreement with the Organization and applicable law, not for our own independent purposes.
6. AI Processing
AI-assisted features are powered by Anthropic's Claude API. When a document is uploaded, its contents may be processed by Anthropic to generate extractions and summaries. Some documents may first be processed by a document-parsing provider (LlamaIndex / LlamaParse) to extract text and structure before AI analysis.
Under Anthropic's current commercial API terms, Anthropic does not use API inputs or outputs to train its models, and Civentry has not opted into any data-sharing or model-improvement program. Anthropic and our parsing provider process this data as service providers/subprocessors to provide the AI functionality, each under a data processing agreement. AI outputs are drafts that require human review before they are published or shared; see our AI Disclaimer & Governance Statement.
7. Aggregated and De-Identified Information
We may create and use aggregated or de-identified information, including for analytics, benchmarking features, and improving the Service. Where we use de-identified information, we will: (a) take reasonable measures to ensure the information cannot be associated with, or reasonably linked to, an individual, Organization, or household; (b) publicly commit to maintain and use the information only in de-identified form and not attempt to re-identify it, except as permitted by law; and (c) contractually require any recipient of de-identified information to comply with the same restrictions.
Our community benchmarking features use only de-identified, aggregated figures presented at or above a minimum sample size, and never expose an individual Organization's identifiable data to another Organization.
8. How We Share Information (Service Providers / Subprocessors)
We share information only with service providers necessary to operate the Service, each bound by a data processing agreement that limits their use of the information to providing services to us:
| Provider | Purpose |
|---|---|
| Supabase | Database, authentication, and document storage |
| Anthropic | AI analysis of documents |
| LlamaIndex / LlamaParse | Document parsing and text extraction from uploaded files |
| Stripe | Payment processing |
| Vercel | Application hosting |
| Resend | Transactional email delivery |
We maintain a current list of subprocessors and will provide notice of material changes as required by our customer agreements and applicable law.
We may also disclose information if required by law or valid legal process, to protect the rights, property, or safety of Civentry, our users, or others, or in connection with a merger, acquisition, financing, or sale of assets, in which case we will require the recipient to honor this Policy or will provide notice and choices as required by law.
The documents and data Organizations upload are not sold or shared. When we act as a service provider/processor for an Organization, the Organization's provision of data to us is not a "sale," and we are contractually restricted from retaining, using, or disclosing that data outside our direct business relationship with the Organization. We do not use that uploaded content for advertising.
Separately, our marketing website uses privacy-focused, first-party analytics to understand site usage (see Section 15). We do not use third-party advertising or retargeting pixels, and we do not sell or share personal information for cross-context behavioral advertising or targeted advertising. If we adopt such technologies in the future, we will update this Policy before doing so and provide the opt-out choices and universal opt-out signal recognition that applicable law requires (see Sections 15 and 18).
9. Residents and Other Individuals Whose Data an Organization Uploads
If you are a resident or member of a community association, your personal information may appear in documents your HOA or its management firm uploaded to Civentry (for example, in a delinquency report or a resident-summary distribution list).
For that information, your HOA (or its management firm) is the controller and decides what is collected, uploaded, and shared. Civentry processes it only on the Organization's behalf. Because of this:
- Direct your privacy requests to your HOA or management firm first. They control the data and can act on requests such as access, correction, or deletion directly.
- We will assist the Organization in responding to verified resident requests, and we will not respond to a resident request independently except as instructed by the Organization or as required by law.
- The Organization is responsible for providing residents any notices required by law regarding data it uploads, and for having the authority to upload it.
Residents do not have direct access to raw financial documents or unpublished AI outputs. Residents see only board-approved, resident-safe content the Organization chooses to share.
10. Data Retention and Deletion
- We retain Organization documents and data for the duration of the active subscription.
- After cancellation, data is retained for 90 days and then permanently deleted, unless we are required to retain it to comply with law, resolve disputes, or enforce our agreements (for example, a litigation hold), in which case we isolate and protect it and delete it when the obligation ends.
- An Organization may request immediate deletion of specific documents; deletion is permanent and not reversible.
- Audit logs are retained for at least 12 months for security and compliance.
11. Your Privacy Rights
Depending on the state in which you live, you may have some or all of the following rights regarding personal information for which Civentry is the controller:
- Know / access what personal information we collect about you and how it is used, and obtain a copy;
- Delete personal information we hold about you, subject to legal exceptions;
- Correct inaccurate personal information;
- Opt out of sale or sharing of personal information for cross-context behavioral advertising; we do not sell or share personal information for this purpose, so there is nothing to opt out of today, and if that ever changes we will update this Policy and honor recognized opt-out preference signals, including the Global Privacy Control (GPC) (see Section 15);
- Opt out of certain profiling that produces legal or similarly significant effects, Civentry does not make such automated decisions about individuals;
- Non-discrimination / non-retaliation, you will receive equal service regardless of the privacy choices you make.
To exercise these rights, contact hello@civentry.com. We will acknowledge and respond to verifiable requests within the timeframes required by applicable law (generally within 45 days, with one possible extension). To protect your information, we will take reasonable steps to verify your identity before acting on a request, and we may decline requests we cannot verify. You may use an authorized agent to submit a request on your behalf, subject to verification. Depending on your state, you may also have the right to appeal a decision on your request and to lodge a complaint with your state regulator or Attorney General.
If your information was uploaded by an HOA or management firm, see Section 9, those requests are generally directed to the Organization as controller.
Additional state-specific rights and procedures are described in Section 18 below.
12. Security
We protect information using role-based access enforced at the database level, tenant isolation between Organizations, encryption in transit (TLS 1.2 minimum, TLS 1.3 preferred) and at rest (AES-256), private document storage with short-lived signed access URLs, multi-factor authentication available for administrative roles, and audit logging. No system is perfectly secure, but security is built into our architecture. See our Security & Data Handling page for detail.
13. Data Breach Notification
In the event of a breach involving personal information, we will notify affected parties and any required authorities without unreasonable delay and within the timeframes required by applicable law, including California's data-breach notification requirements (Cal. Civ. Code §§ 1798.29, 1798.82, as amended), subject to the legitimate needs of law enforcement.
Where Civentry acts as a service provider/processor for an Organization (Section 2), we will notify the Organization without undue delay after becoming aware of a breach affecting its data, and will reasonably assist the Organization in meeting its own notification obligations to residents and regulators. Where Civentry is the controller, we will notify affected individuals and regulators directly as required.
14. Children's Privacy
The Service is intended for use by adults acting on behalf of community associations, and you must be at least 18 years old to create an account. The Service is not directed to children, and we do not knowingly collect personal information from children.
15. Cookies and Tracking Technologies
We use cookies and similar technologies in two categories:
Strictly necessary (first-party). We use first-party cookies to operate the Service, for example, to keep you signed in, maintain your session, remember basic preferences, and protect the security and integrity of the platform. These are essential and cannot be turned off through the Service without affecting how it works.
Analytics (first-party, privacy-focused). We use privacy-focused analytics to understand, in aggregate, how our marketing site is used, so we can improve it. We do not use third-party advertising or retargeting pixels (for example, the Meta pixel or Google advertising tags), and we do not sell or share personal information for cross-context behavioral advertising or targeted advertising. Our analytics do not access the contents of the financial documents an Organization uploads.
Your choices. Because we do not use advertising or retargeting pixels and do not sell or share personal information for advertising, there is no advertising opt-out to exercise today. You can still control cookies through your browser settings. If we adopt advertising technologies in the future, we will update this Policy first, provide a clear opt-out, and honor recognized universal opt-out preference signals such as the Global Privacy Control (GPC), as described in Section 18.
Most browsers let you block or delete cookies through their settings; blocking strictly necessary cookies may affect how the Service functions.
16. Changes to this Policy
We may update this Policy. We will post the updated version with a new "Last updated" date and provide additional notice for material changes as required by law.
17. Contact
Privacy questions or requests: hello@civentry.com
Daddisyn Labs, LLC, Moorpark, California
18. U.S. State Privacy Rights
This section provides additional information for residents of U.S. states that have enacted consumer privacy laws. It explains the rights those laws provide and how to exercise them, and should be read together with the rest of this Policy. For residents of a state with such a law, the rights and procedures described in this section apply to the extent that state's law applies to us.
These laws apply to a business only when it meets that state's applicability thresholds (for example, processing the personal data of a defined number of state residents, or meeting revenue or data-sale criteria). We honor the rights below to the extent a state's law applies to us, and we apply privacy-protective practices across our service regardless.
18.1 A reminder about our two roles
As explained in Section 2, Civentry handles personal information in two capacities:
- As a controller, for your account, billing, and usage information. The rights below apply to that information, and you can exercise them with us directly.
- As a service provider / processor, for the documents and data an association or its management firm uploads, including resident information. For that information, the association (or its management firm) is the controller. If you are a resident exercising rights over information your association uploaded, direct your request to your association or its management firm; we will assist them as the law requires.
18.2 Rights available under state privacy laws
Depending on your state, you may have some or all of the following rights regarding personal information for which Civentry is the controller:
- Right to confirm and access the personal data we process about you, and to obtain a copy in a portable, readily usable format.
- Right to correct inaccurate personal data.
- Right to delete personal data, subject to legal exceptions.
- Right to opt out of the sale of personal data, of targeted advertising, and of profiling in furtherance of decisions that produce legal or similarly significant effects.
- Right to opt in before we process sensitive personal data, in states that require opt-in consent.
- Right to appeal a denial of a request, in states that provide an appeal process.
- Right to non-discrimination and non-retaliation for exercising your rights.
18.3 How these rights apply to Civentry
Several of these rights concern practices Civentry does not engage in, and we want to be clear about that:
- We do not sell or share personal information for advertising. We use privacy-focused, first-party analytics and do not use third-party advertising or retargeting pixels (see Section 15). Because we do not sell or share personal information for cross-context behavioral advertising or targeted advertising, there is no such activity to opt out of. If this changes, we will update this Policy and honor recognized opt-out preference signals, including the Global Privacy Control (GPC).
- We do not use the contents of the documents an Organization uploads for advertising, and those documents are not shared with our advertising or analytics providers.
- We do not make decisions about individuals through solely automated processing that produce legal or similarly significant effects. Our AI features generate drafts that a human reviews and approves; people make the decisions. See our AI Disclaimer & Governance Statement.
- We do not intentionally collect sensitive personal data (such as Social Security numbers, full financial-account numbers, or health information) and instruct customers not to upload it. Where a state requires opt-in consent before processing sensitive data, and such data is present in documents an association uploads, we rely on the association, as controller, to have obtained any required consent and provided any required notice; our Data Processing Agreement requires the association to do so.
18.4 Universal opt-out mechanisms
Several U.S. states require businesses that sell or share personal information, or that conduct targeted advertising, to recognize universal opt-out preference signals such as the Global Privacy Control (GPC). States that currently require recognition of such a mechanism include California, Colorado, Connecticut, Delaware, Maryland, Minnesota, Montana, New Hampshire, New Jersey, Oregon, and Texas. Civentry does not sell or share personal information for cross-context behavioral advertising or targeted advertising, so there is currently no such processing for these signals to limit. If we begin any activity that constitutes a sale, a sharing, or targeted advertising, we will update this Policy and honor recognized universal opt-out preference signals, including the GPC, as required by applicable law.
18.5 How to exercise your rights
To submit a request, contact hello@civentry.com. So we can protect your information, we will take reasonable steps to verify your identity before acting, and we may request additional information for that purpose. If we cannot verify your identity, we may decline the request.
- Authorized agents. You may use an authorized agent to submit a request on your behalf. We may require proof of the agent's authority and verification of your identity.
- Response time. We will respond within the time your state's law allows, generally within 45 days, with one extension where permitted, or a shorter period where a state requires it.
- Appeals. If we deny your request and your state provides an appeal right, you may appeal by replying to our decision or contacting hello@civentry.com. We will respond to your appeal within the period your state's law allows and explain our decision. If your appeal is denied, you may contact your state Attorney General or privacy regulator.
18.6 States with comprehensive consumer privacy laws
The following states have comprehensive consumer privacy laws under which their residents may have the rights described above, to the extent the law applies to us:
| State | Law |
|---|---|
| California | California Consumer Privacy Act (CCPA), as amended by the CPRA |
| Colorado | Colorado Privacy Act (CPA) |
| Connecticut | Connecticut Data Privacy Act (CTDPA) |
| Delaware | Delaware Personal Data Privacy Act (DPDPA) |
| Florida | Florida Digital Bill of Rights (FDBR) |
| Indiana | Indiana Consumer Data Protection Act |
| Iowa | Iowa Consumer Data Protection Act |
| Kentucky | Kentucky Consumer Data Protection Act |
| Maryland | Maryland Online Data Privacy Act (MODPA) |
| Minnesota | Minnesota Consumer Data Privacy Act |
| Montana | Montana Consumer Data Privacy Act |
| Nebraska | Nebraska Data Privacy Act |
| New Hampshire | New Hampshire Privacy Act |
| New Jersey | New Jersey Data Privacy Act |
| Oregon | Oregon Consumer Privacy Act (OCPA) |
| Rhode Island | Rhode Island Data Transparency and Privacy Protection Act |
| Tennessee | Tennessee Information Protection Act (TIPA) |
| Texas | Texas Data Privacy and Security Act (TDPSA) |
| Utah | Utah Consumer Privacy Act (UCPA) |
| Virginia | Virginia Consumer Data Protection Act (VCDPA) |
The specific rights, applicability thresholds, and procedures vary by state. The rights and processes described in this section apply to the extent the relevant state law applies to Civentry. Most of these laws are enforced by the state Attorney General; California is also enforced by the California Privacy Protection Agency and provides a limited private right of action for certain data-breach claims.
18.7 Additional state notices
California. In addition to the rights above, California residents have the right to know the categories of personal information we collect, the sources, the business purposes for collection, and the categories of third parties to whom we disclose it, all of which are described in this Policy. We do not sell or share personal information for cross-context behavioral advertising, so there is no such activity for California residents to opt out of; if that changes, we will update this Policy and honor the Global Privacy Control (GPC) (see Section 15). Civentry is not a data broker.
Nevada. Nevada law gives consumers the right to direct a business not to sell certain covered personal information. Civentry does not sell personal information; if you wish to confirm or submit a request, contact hello@civentry.com.
Consumer health data (Washington, Nevada, and similar laws). Some states regulate "consumer health data." Civentry does not collect health or medical information and is not designed to receive it. If you believe health information has been provided to us through a document upload, contact us so it can be addressed.
You also have the right to lodge a complaint with your state Attorney General or privacy regulator.