← PathReader

Privacy Policy for PathReader AI

Effective Date: July 15, 2026 · Last Updated: July 15, 2026

1. Introduction

PathReader AI LLC (“PathReader,” “we,” “our,” or “us”) is a Delaware limited liability company that operates the website located at pathreader.ai. PathReader is the data controller responsible for the personal information described in this Privacy Policy.

This Privacy Policy explains how we collect, use, share, and protect personal information when you visit our website or contact us through the website or by email (for example, at [email protected]). It applies to all visitors of pathreader.ai and individuals who submit inquiries or briefing requests through the site.

If you are a customer of the PathReader platform or API, this Privacy Policy applies to your interactions with the pathreader.ai website only (for example, browsing, submitting support requests, or receiving marketing communications). The processing of Customer Data within the platform and API is governed exclusively by the applicable Master Subscription Agreement and Data Processing Agreement between you (or your organization) and PathReader.

By accessing or using our website, you acknowledge that you have read and understood this Privacy Policy.

2. Information We Collect

We collect personal information in the following categories when you interact with the pathreader.ai website.

  1. Information You Provide Directly: When you submit the Request Briefing form or send an email to [email protected], we collect your name, email address, company name, and job title, along with any other information you choose to include in your message.
  2. Information Collected Automatically: When you visit our website, we automatically collect certain technical data, including your IP address, browser type, operating system, and device information, through server logs and strictly necessary cookies as described in Section 5.
  3. Information from Third-Party Sources: We may obtain business contact information from referral partners, publicly available professional networking platforms (such as LinkedIn), industry directories, and conference or event attendee lists. When we collect your personal information from a source other than you, we will inform you of that source and the purposes of our processing within a reasonable period and in accordance with applicable law.

3. How We Use Your Information

We process the personal information we collect for the following purposes:

  1. Responding to your briefing requests, inquiries, and other communications submitted through the website or directed to [email protected].
  2. Communicating with you about our products, services, and updates that may be relevant to your business.
  3. Operating, maintaining, and improving the pathreader.ai website and its functionality.
  4. Analyzing website traffic and usage patterns to better understand how visitors interact with our site.
  5. Complying with applicable legal obligations, regulatory requirements, and lawful requests from public authorities.
  6. Protecting the rights, property, safety, and security of PathReader, our users, and the public, including detecting and preventing fraud or other prohibited activities.
  7. We may generate and use aggregated, de-identified data derived from website visitor interactions that does not identify you or any individual, for purposes of analyzing trends, improving our website and services, and developing benchmarks.

4. Legal Bases for Processing

If you are located in the European Economic Area, the United Kingdom, or Switzerland, we rely on the following legal bases under the General Data Protection Regulation (GDPR) when processing your personal data:

  1. Consent: Where you have provided your affirmative consent, such as opting in to receive marketing communications. You may withdraw consent at any time by contacting us at [email protected].
  2. Legitimate Interests: We process personal data where necessary for our legitimate business interests, provided those interests are not overridden by your rights. These interests include website analytics, business development, fraud prevention, and network security.
  3. Performance of a Contract or Pre-Contractual Steps: We process personal data as necessary to respond to your briefing requests, answer inquiries, and take steps at your request prior to entering into an agreement.
  4. Compliance with Legal Obligations: We process personal data where required to comply with applicable laws, regulations, or legal processes.

5. Cookies and Tracking Technologies

The pathreader.ai website uses only strictly necessary cookies to operate effectively and securely. The following table describes the cookies we use.

Cookie TypePurpose
Strictly Necessary Cookies Required for basic website functionality, such as page navigation and access to secure areas. These cookies cannot be disabled.

We use only strictly necessary cookies. We do not use analytics, advertising, or functional cookies, and we do not display a cookie consent banner. You may manage or disable cookies through your browser settings; however, disabling strictly necessary cookies may limit the functionality of the website.

6. How We Share Your Information

We do not sell, rent, or trade your personal information. We may share your information only in the following limited circumstances:

  1. Service Providers and Processors: We share personal information with third-party vendors who assist us in operating our website and business, including hosting providers, email service providers, and analytics platforms. These providers are contractually obligated to use your data solely on our behalf and in accordance with this Policy.
  2. Legal Requirements: We may disclose personal information if required to do so by law, regulation, legal process, or enforceable governmental request, or where disclosure is necessary to protect our rights, safety, or property, or the rights, safety, or property of others.
  3. Business Transfers: In connection with a merger, acquisition, reorganization, or sale of all or a portion of our assets, your personal information may be transferred to the acquiring entity. We will provide notice of any such transfer and any choices you may have regarding your information.

7. Data Retention

PathReader retains personal information only for as long as reasonably necessary to fulfill the purposes described in this Privacy Policy, or as required or permitted by applicable law. When determining the appropriate retention period for your personal information, we consider the following criteria:

  1. The nature and sensitivity of the personal information collected.
  2. The purposes for which the information was collected and processed.
  3. Whether those purposes can be achieved through other means.
  4. Applicable legal, regulatory, or contractual obligations that require retention for a specified period (for example, tax, accounting, or reporting requirements).
  5. Applicable statutes of limitations under which claims could be brought.
  6. The existence of any pending or anticipated disputes or investigations.

When personal information is no longer required for any of the purposes described above, we will securely delete or anonymize it in accordance with applicable law and our internal data management procedures. If deletion or anonymization is not immediately possible (for example, because the information is stored in backup archives), we will isolate the information from further processing until deletion can be completed.

As a general guide, we retain the following categories of website-collected data for the periods indicated: contact information and communications submitted through briefing requests or inquiries, for 24 months following our last interaction with you; and automatically collected technical data, including IP addresses, browser information, and usage logs, for 12 months from collection.

8. Your Privacy Rights

Depending on your location and applicable law, you may have certain rights regarding your personal information.

  1. GDPR Rights. If you are located in the European Economic Area or the United Kingdom, you may exercise the following rights: access to your personal data; rectification of inaccurate data; erasure of your data; restriction of processing; data portability; objection to processing; and withdrawal of consent at any time.
  2. US State Privacy Rights. If you are a resident of a US state with an applicable comprehensive privacy law, including California, Washington, Colorado, Connecticut, Virginia, Texas, Oregon, and other states with similar legislation, you may have rights to access the personal information we hold about you, request correction of inaccurate information, request deletion of your personal information, obtain a copy of your data in a portable format, and opt out of the sale or sharing of personal information or targeted advertising. We do not sell or share your personal information as those terms are defined under applicable state privacy laws. You will not receive discriminatory treatment for exercising your privacy rights.
  3. Additional Rights. We do not engage in automated decision-making, including profiling, that produces legal or similarly significant effects concerning you. If you submit a privacy rights request and we decline to take action, you may appeal our decision by contacting us at [email protected]. We will respond to your appeal within the timeframe required by applicable law.
  4. Exercising Your Rights. To exercise any of the rights described above, please contact us at [email protected]. We will respond to verified requests within the timeframes required by applicable law.

9. International Data Transfers

PathReader is based in the United States. If you access our website or contact us from outside the United States, your personal data may be transferred to, stored in, and processed in the United States, where data protection laws may differ from those in your jurisdiction. Where we transfer personal data from the European Economic Area, the United Kingdom, or Switzerland to the United States, we rely on appropriate safeguards to ensure that such transfers comply with applicable data protection laws. These safeguards may include:

  1. Standard contractual clauses approved by the European Commission or the UK Information Commissioner’s Office, as applicable;
  2. Other valid transfer mechanisms recognized under applicable law.

To obtain further information about the safeguards we have in place for international data transfers, please contact us at [email protected].

PathReader is not established in the European Economic Area or the United Kingdom and does not currently target or process personal data of individuals in those jurisdictions. If PathReader begins processing personal data of individuals in the European Economic Area or the United Kingdom in the future, PathReader will appoint a representative in the applicable jurisdiction in accordance with Article 27 of the GDPR or the UK GDPR, as applicable, and will update this Privacy Policy with the representative’s contact details.

10. Security

PathReader implements reasonable administrative, technical, and organizational measures designed to protect personal information against unauthorized access, alteration, disclosure, destruction, or loss. These measures include, but are not limited to:

  1. Encryption of data in transit and at rest;
  2. Access controls limiting personnel access to personal information on a need-to-know basis;
  3. Regular review of information collection, storage, and processing practices;
  4. Use of secure hosting infrastructure with appropriate physical and environmental safeguards.

We regularly evaluate and update our security practices to address evolving risks. However, no method of electronic transmission or data storage is entirely secure. While we strive to protect your personal information, we cannot guarantee absolute security. If you have reason to believe that your interaction with us is no longer secure, please contact us immediately at [email protected].

11. Children’s Privacy

The pathreader.ai website and our services are not directed at individuals under the age of 16. PathReader does not knowingly collect, solicit, or maintain personal information from anyone under 16 years of age.

If we become aware that we have collected personal information from a child under 16 without verification of parental consent, we will take prompt steps to delete that information from our systems. If you believe that we may have inadvertently collected personal information from a child under 16, please contact us at [email protected] so that we can investigate and take appropriate action.

12. Enterprise Platform and API Data

If you are a customer of the PathReader platform or API, or an employee or end user of such a customer, the processing of data within those services is governed by the Master Subscription Agreement and Data Processing Agreement (“DPA”) between PathReader and the applicable customer organization, not by this Privacy Policy.

Data processed through the PathReader platform and API may include policy documents, rule candidates, policy sets, and compliance-check request data. Such data may contain personal information belonging to the customer’s end users or other individuals. PathReader processes this data as a data processor (or service provider, as applicable under the CCPA/CPRA) on behalf of the customer, in accordance with the customer’s documented instructions as set forth in the DPA.

If you have questions about how a PathReader customer handles your personal data through the platform or API, please contact that customer directly.

13. Changes to This Privacy Policy

We may update or modify this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make changes, we will revise the “Last Updated” date at the top of this policy.

If we make material changes to how we collect, use, or share your personal information, we will notify you by posting the revised Privacy Policy on the pathreader.ai website. Where required by applicable law, we will provide additional notice, such as by sending an email to the address associated with your account or inquiry.

We encourage you to review this Privacy Policy periodically to stay informed about our data practices. Where we rely on consent as the legal basis for processing, we will obtain renewed consent to the extent required by applicable law following material changes to this Privacy Policy. Your continued use of the website after changes to this Privacy Policy constitutes your acknowledgment of the updated terms.

14. Contact Us

If you have any questions about this Privacy Policy, wish to exercise your privacy rights, or have concerns about how we handle your personal information, please contact us using the information below.

PathReader AI LLC
Email: [email protected] (general inquiries) / [email protected] (privacy and data protection)
Online: the contact form on our website at pathreader.ai
Mailing Address:
2226 Eastlake Ave E #1432
Seattle, WA 98102
United States

We will make reasonable efforts to respond to all legitimate inquiries within a timely manner and, in any event, within any timeframe required by applicable law.