Privacy Policy
ReadiVault, Inc.
Effective Date: May 1, 2026 Last Updated: June 15, 2026
1. Introduction and Scope
ReadiVault, Inc. ("ReadiVault," "we," "us," or "our") provides a procurement-readiness platform and related websites, applications, and services (collectively, the "Service") that help suppliers and organizations measure, understand, and improve their readiness to participate in procurement across four markets: Federal Government, State Government, Local Government, and the Private Sector.
This Privacy Policy explains how we collect, use, disclose, retain, and protect information in connection with the Service, including the marketing and call-to-action sites located at [whyreadiness.readivault.com] and [www.readivault.com] (together with the platform, the "Sites").
This Policy applies to information we process as a business/controller—that is, when we determine the purposes and means of processing. When we process information solely on behalf of, and under the instructions of, an organization that subscribes to the Service (for example, an employer, agency, or procuring organization), we act as that organization's service provider/processor, and that organization's privacy notice and any applicable agreement govern that processing. In case of conflict for such processing, the customer agreement controls.
By accessing or using the Service, you acknowledge that you have read and understood this Policy. If you do not agree, do not use the Service.
2. Who We Are; How to Contact Us
The controller responsible for your information is:
ReadiVault, Inc. Washington, DC Privacy inquiries: privacy@readivault.com Data-rights requests: privacy@readivault.com
3. Key Definitions
- "Account" means a registered user profile used to access the Service.
- "Customer" / "Subscribing Organization" means an entity that subscribes to a paid plan.
- "Supplier" means an individual or organization that uses the Service to assess or present its procurement readiness.
- "Procuring Organization" means a government agency (federal, state, or local) or private-sector buyer that receives Supplier information through the Service.
- "Readiness Inputs" means data, documents, and signals used to generate readiness assessments (for example, registrations, certifications, financial indicators, security and compliance artifacts, and performance information).
- "Readiness Output" means the standardized readiness assessment, score, or profile generated by the Service.
- "Consent Engagement Loop" means the consent-based mechanism through which a Supplier authorizes the disclosure of specified information to one or more Procuring Organizations.
- "AI Features" means the automated coaching, analysis, drafting, and assessment features of the Service powered by our proprietary and third-party artificial-intelligence models.
- "Personal Information" has the meaning given under applicable data-protection law and refers to information that identifies, relates to, or could reasonably be linked to an identified or identifiable individual.
4. Information We Collect
We collect the categories of information described below. Not every category applies to every user.
4.1 Information You Provide Directly
- Account and identity data: name, business email, phone number, job title, username, and password/credentials.
- Organization data: company or agency name, entity type, market segment (Federal, State, Local, or Private Sector), size band, industry codes (e.g., NAICS/PSC), and location.
- Readiness Inputs: registrations and identifiers, certifications and status designations, financial and stability indicators, cybersecurity and compliance artifacts (including, where you provide them, materials relevant to CMMC or similar frameworks), past-performance information, and supporting documentation you upload.
- Payment data: billing contact, billing address, and the subscription plan selected. Card and bank details are collected and processed by our third-party payment processor; we do not store full payment-card numbers.
- Communications: messages, support requests, survey responses, and content you submit through the Sites or the Consent Engagement Loop.
4.2 Information from Third-Party and Government Sources
To generate standardized readiness assessments, we obtain information from public and authorized sources, which may include federal procurement data systems and commercial data providers—for example, publicly available registration, award, spending, and business-status data.
Access to gated or authenticated government systems occurs only where authorized. Certain systems (for example, supplier performance data behind federal authentication) are accessible only through gated credentials and are obtained solely through consent-brokered mechanisms with appropriate authorization. We do not represent that we have unrestricted or direct programmatic access to any government system that does not provide one.
4.3 Information Collected Automatically
- Device and technical data: IP address, browser type, operating system, device identifiers, and language settings.
- Usage data: pages viewed, features used, actions taken, timestamps, referring/exit pages, and session activity.
- Cookies and similar technologies: as described in Section 10.
4.4 AI Interaction Data
When you use AI Features, we process the prompts, questions, documents, and other inputs you submit, along with the resulting outputs and associated metadata, to provide, secure, and improve those features, subject to Section 6.6.
5. Sources of Information
We collect information: (a) directly from you; (b) automatically through your use of the Service; (c) from Subscribing Organizations and their authorized users; (d) from Procuring Organizations acting through the Consent Engagement Loop; (e) from public and government data sources; and (f) from service providers, including analytics, payment, security, and data-enrichment vendors.
6. How We Use Information
We use information for the following purposes:
6.1 To Provide and Operate the Service
Create and manage Accounts; authenticate users; deliver platform functionality; generate, display, and update Readiness Outputs across all four markets; and enable the Consent Engagement Loop.
6.2 To Compute Readiness Assessments
Combine Readiness Inputs and authorized third-party data to produce standardized, market-conditioned readiness assessments and related coaching and recommendations.
6.3 To Facilitate Consent-Based Engagement
Enable Suppliers to authorize, scope, and revoke the disclosure of specified information to Procuring Organizations, and to enable Procuring Organizations to receive only the information a Supplier has consented to share.
6.4 To Process Transactions
Manage subscriptions, billing, renewals, and related communications.
6.5 To Communicate
Send service, security, transactional, and administrative messages; respond to inquiries; and, where permitted, send marketing communications from which you may opt out.
6.6 To Provide and Improve AI Features
Operate our AI-powered coaching, analysis, and assessment features. We do not use identifiable Customer Content or Readiness Inputs to train artificial-intelligence models that are made generally available to other customers, except with authorization or where the data has been aggregated and de-identified so that it no longer reasonably identifies any individual or organization. We may use de-identified and aggregated data to develop, benchmark, and improve the Service, including our models and scoring methodology.
6.7 To Secure and Protect
Monitor for, prevent, detect, and respond to fraud, abuse, security incidents, and unauthorized or unlawful activity; enforce our Terms; and protect the rights, safety, and property of ReadiVault, our users, and others.
6.8 To Analyze and Develop
Understand usage, conduct research and analytics, improve existing features, and develop new products and services.
6.9 To Comply with Law
Comply with applicable legal obligations, respond to lawful requests, and establish, exercise, or defend legal claims.
7. The Consent Engagement Loop
The Consent Engagement Loop is central to the Service and to how we protect Supplier information.
- Supplier-controlled disclosure. Information about a Supplier is disclosed to a Procuring Organization only when the Supplier authorizes that disclosure, and only within the scope the Supplier selects.
- Scope and duration. Consent may be scoped by recipient, by category of information, and by time period. We honor the scope you set.
- Revocation. A Supplier may withdraw consent at any time through the Service. Withdrawal stops future disclosures to the affected recipient but does not, by itself, retrieve information a recipient already received.
- Recipient obligations. Procuring Organizations receive information subject to the Terms and applicable law; ReadiVault does not control a recipient's independent use of information after authorized disclosure, and each recipient is responsible for its own compliance.
- Accuracy. Suppliers are responsible for the accuracy and currency of the Readiness Inputs they provide and authorize for disclosure.
8. How We Share and Disclose Information
We share information only as described below. We do not sell your Personal Information, and we do not "share" Personal Information for cross-context behavioral advertising, as those terms are defined under applicable U.S. state privacy laws.
- With Procuring Organizations through the Consent Engagement Loop, subject to Supplier consent and scope.
- With Subscribing Organizations and their authorized administrators, for users associated with that organization's Account.
- With service providers and subprocessors that perform functions on our behalf—such as cloud hosting and inference infrastructure, payment processing, analytics, security, communications, and customer support—under contracts that restrict their use of information to providing services to us.
- For legal and safety reasons, where we believe disclosure is required or permitted by law; to respond to lawful requests, subpoenas, or legal process; to enforce our agreements; or to protect the rights, property, or safety of ReadiVault, our users, or others.
- In connection with a corporate transaction, such as a merger, acquisition, financing, reorganization, or sale of assets, in which case information may be transferred subject to this Policy.
- In aggregated or de-identified form that does not reasonably identify any individual or organization, for research, benchmarking, product development, and other lawful purposes.
9. Government and Public Data Sources; Accuracy Disclaimer
The Service incorporates information from government and third-party sources. ReadiVault does not control, and does not guarantee the accuracy, completeness, currency, or availability of, information obtained from government systems or third-party providers. The authoritative source for any government record is the government system of record itself. Readiness Outputs are informational and decision-support tools and are not a substitute for a Procuring Organization's own due diligence or a government system of record.
10. Automated Processing and AI Features
The Service uses automated processing and AI Features to generate Readiness Outputs, coaching, and recommendations. Readiness Outputs and AI-generated content are informational and are intended to support—not replace—human judgment. ReadiVault does not use the Service to make decisions producing legal or similarly significant effects about an individual based solely on automated processing without a lawful basis and appropriate safeguards. AI Features may produce inaccurate or incomplete results and should be independently verified before you rely on them. See the Terms of Service for additional disclaimers.
11. Cookies and Tracking Technologies
We and our service providers use cookies, pixels, local storage, and similar technologies to operate the Sites, remember preferences, authenticate sessions, measure performance, and understand usage. You can control cookies through your browser settings and, where offered, through our cookie-preference controls. Some features may not function properly if you disable certain cookies. Where required, we obtain consent before setting non-essential cookies.
12. Data Retention
We retain information for as long as necessary to provide the Service, maintain your Account, comply with our legal obligations, resolve disputes, enforce our agreements, and for the legitimate business purposes described in this Policy. Retention periods vary by data type and context. When information is no longer required, we delete, de-identify, or archive it in accordance with our retention practices and applicable law.
13. Data Security
We maintain administrative, technical, and physical safeguards designed to protect information appropriate to its sensitivity and the risks involved, including access controls, encryption in transit, monitoring, and least-privilege practices. Because many of our users are government contractors and organizations with heightened security expectations, we design our controls with those expectations in mind. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your credentials and for activity that occurs under your Account.
14. Your Privacy Rights
Depending on your jurisdiction and role, you may have some or all of the following rights regarding your Personal Information:
- Access / Know — to request the categories and specific pieces of Personal Information we have collected.
- Correction — to request correction of inaccurate Personal Information.
- Deletion — to request deletion, subject to legal exceptions.
- Portability — to obtain a copy in a portable format.
- Opt out of "sale" or "sharing" — although we do not sell or share Personal Information as defined by applicable law.
- Limit use of sensitive Personal Information — to the extent we process any such information.
- Non-discrimination — you will not be discriminated against for exercising your rights.
- Appeal — where provided by law, to appeal a decision on your request.
How to exercise your rights. Submit a request to privacy@readivault.com. We will verify your identity before acting and will respond within the timeframes required by applicable law. You may use an authorized agent where permitted; we may require proof of authorization. If we act as a service provider/processor for a Subscribing Organization, we will direct your request to that organization or handle it under our contract with them.
State-specific notice. Residents of California, Virginia, Colorado, Connecticut, Utah, and other states with comprehensive privacy laws have the rights described above to the extent those laws apply. California residents may also request information about disclosures for direct-marketing purposes.
15. Children's Privacy
The Service is a business-to-business tool intended for use by professionals and organizations. It is not directed to children, and we do not knowingly collect Personal Information from anyone under 18. If you believe a minor has provided us information, contact privacy@readivault.com and we will take appropriate steps to delete it.
16. Data Location and International Users
The Service is operated in and directed to the United States, and information is processed and stored in the United States. Where the Service supports users with government data-residency requirements, we process such data consistent with applicable requirements. If you access the Service from outside the United States, you do so on your own initiative and are responsible for compliance with local law, and you understand your information will be processed in the United States.
17. Do Not Track
Some browsers offer "Do Not Track" signals. Because there is no common industry standard for responding to them, the Sites do not currently respond to Do Not Track signals. We honor recognized opt-out preference signals where required by applicable law.
18. Third-Party Links and Services
The Sites may link to third-party websites and integrate third-party services. We are not responsible for the privacy practices of third parties. Review their policies before providing information.
19. Changes to This Policy
We may update this Policy from time to time. When we make material changes, we will update the "Last Updated" date and, where required, provide additional notice. Your continued use of the Service after an update constitutes acceptance of the revised Policy to the extent permitted by law.
20. Contact Us
ReadiVault, Inc. Washington, DC 20009 privacy@readivault.com
This Privacy Policy is provided for the ReadiVault Service and the Sites identified above. It should be read together with the ReadiVault Terms of Service.
