Privacy Policy
How Hepner Corp handles personal information in the HepnerSync Portal and Marketplace
Effective and last updated: August 30, 2025
Published at: https://www.hepnercorp.com/HS-PP
Notice at Collection. We collect account and business contact details, subscription and payment records, device and usage data, support communications, integration connection data, and information a Customer chooses to place in the Services. We use it to provide, secure, bill, support, and improve the Services; operate requested integrations and custom development; communicate with Users; and meet legal obligations. We do not sell personal information for money or share it for cross-context behavioral advertising. Retention is based on the account term, the Customer's instructions, security and backup cycles, and legal or accounting requirements, as explained below.
Use of the Portal is also governed by the HepnerSync Portal Terms of Service at https://www.hepnercorp.com/HS-TOS. The Terms explain subscriptions, Customer Data responsibilities, security, custom development, and liability allocation.
1. Scope
This Privacy Policy explains how Hepner Corp and its HepnerSync division ("HepnerSync," "we," "us," or "our") collect, use, disclose, retain, and protect personal information through the HepnerSync Portal, Marketplace, Modules, websites that link to this Policy, support channels, and related business interactions (collectively, the "Services").
The Services are designed for businesses and organizations. This Policy covers business contacts and Users even when privacy law treats their information as personal information. It does not govern an unrelated website, product, or service that has its own privacy notice.
2. Our Two Privacy Roles
2.1 Account and business information
HepnerSync determines why and how it uses information needed to operate its own business, such as account registration, billing, security, website analytics, support, and business communications. For this information, HepnerSync acts as a business, controller, or similar responsible party under applicable law.
2.2 Customer Data
A Customer controls the records, files, personal information, prompts, and other content it places in a Module or directs an integration to process ("Customer Data"). For Customer Data, the Customer generally acts as the business or controller and HepnerSync acts as its service provider or processor. The Customer decides what information to collect and may use a customized Module for purposes that HepnerSync does not know or control. We process Customer Data under the Customer's agreement and instructions. If you are an employee, client, lead, vendor, or other person whose information a Customer placed in the Services, contact that Customer first. We will assist the Customer as required by law and contract.
3. Personal Information We Collect
The categories below include identifiers; customer-record information; commercial information; internet or other electronic network activity; approximate geolocation; audio or other sensory information when support is recorded; professional or employment-related information; inferences; and sensitive personal information when a Customer or supported integration provides it. Not every category is collected from every person.
3.1 Identifiers and account details
We collect names, business email addresses, business phone numbers, usernames, account identifiers, organization names, roles, permissions, mailing addresses, and authentication or multifactor records.
3.2 Commercial, subscription, and payment information
We collect selected Modules, plan and pricing records, order acceptance, annual-term and renewal records, invoices, payment status, transaction identifiers, tax information, and support entitlement. Payment providers may collect card or bank details directly. We ordinarily receive a token, limited account details, last digits, payment status, and related records rather than full payment credentials.
3.3 Internet, device, and usage information
We collect IP address, device and browser type, operating system, session and login data, timestamps, pages and features used, clicks, error records, diagnostic events, performance data, approximate location inferred from IP address, and security or fraud signals.
3.4 Communications and support
We collect messages, emails, meeting notes, call or support records where permitted, attachments, feedback, survey responses, and information provided when reporting a problem or requesting a feature.
3.5 Integration and connection information
When a Customer connects another system, we may process provider and account identifiers, access tokens, API keys, connection settings, field mappings, synchronization status, logs, and data returned by the connected service. We use secure tokens or delegated access when the provider supports them.
3.6 Designer and development information
We collect prompts, requested changes, requirements, generated specifications, acceptance decisions, testing feedback, deployment records, and related technical artifacts. These may be reviewed by HepnerSync personnel and automated development tools to prepare, test, secure, and release requested changes. As explained in the Terms, we may also use Feature Contributions and generalized technical learning to improve the platform or develop Marketplace offerings. We do not include personal information from Customer Data or identify a Customer's nonpublic business information in a general Marketplace offering without permission.
3.7 Customer Data
Customer Data can include records about a Customer's employees, clients, leads, vendors, transactions, schedules, inventory, communications, invoices, finances, banking activity, health-related matters, identity, or other business operations. Its content depends on the Modules, integrations, and the Customer's choices, and we may not know what a Customer has entered. The Customer is responsible for classifying that data, determining whether its configuration is appropriate, limiting access, and meeting legal or industry requirements. Customers should use supported provider tokens or secure connections instead of raw bank-login credentials, security codes, authentication data, or full payment-card credentials whenever available.
3.8 Inferences and derived information
We may derive account-health, security, performance, or feature-use insights from the information above. We do not use Portal account data to make legal, employment, lending, insurance, housing, healthcare, or similarly significant decisions about individuals. A Customer may configure its own Modules to support business decisions, and that Customer is responsible for notices, human review, and legal compliance.
4. Sources of Information
We collect personal information from:
Users and Customers, including information entered during signup, purchasing, configuration, support, and development requests;
Customer administrators, who may create accounts, assign permissions, and provide business records about other Users;
devices, browsers, cookies, logs, and security tools when a person uses the Services;
connected systems and integration providers at the Customer's direction;
payment, identity, communications, hosting, analytics, and support providers;
business partners, referrals, public business directories, and professional networks; and
Customer Data supplied by or for a Customer, which we process on that Customer's behalf.
5. Why We Use Personal Information
We use personal information for the following specific purposes:
Provide the Services. Create and administer accounts; authenticate Users; provide the Portal, reports, Modules, integrations, and requested workflows; and deliver Customer Data to authorized destinations.
Process purchases and contracts. Display and record Module Orders, process payments, issue invoices, administer annual terms and renewals, calculate taxes, and maintain transaction records.
Develop and support Customer configurations. Translate requests into specifications, test changes, conduct senior review, deploy approved changes, troubleshoot defects, maintain release history, and use Feature Contributions and generalized technical learning to improve the platform or develop Marketplace offerings as described in the Terms.
Secure the Services. Detect unauthorized access, fraud, abuse, malware, and reliability issues; investigate incidents; maintain logs; enforce permissions; and protect Customers and HepnerSync.
Provide support and communications. Respond to questions, send service, security, billing, renewal, and legal notices, and communicate about requested work.
Maintain and improve the platform. Analyze performance and feature use, repair errors, improve accessibility and usability, plan capacity, and develop general improvements. We may use aggregated or deidentified information that does not reasonably identify a person or Customer.
Meet legal and business obligations. Comply with law, valid legal process, tax and accounting rules, protect rights and safety, resolve disputes, enforce agreements, and support corporate transactions.
Marketing to business contacts. Send information about HepnerSync products or events where permitted. Recipients can opt out of promotional email at any time. Service and legal messages are not promotional.
6. How We Disclose Personal Information
We disclose personal information only as reasonably necessary for the purposes above, at a Customer's direction, or as permitted by law. Categories of recipients include:
Cloud and technical providers. Hosting, databases, deployment, job processing, content delivery, monitoring, logging, security, backups, and software-development providers.
Payment and business-operation providers. Payment processors, invoicing, tax, customer support, communications, identity, productivity, and professional service providers.
Customer-authorized integrations. Banks, CRMs, ERPs, payroll systems, record systems, communications platforms, and other services the Customer chooses to connect.
The Customer and authorized Users. Administrators and Users can access information according to Customer-assigned roles and permissions.
Professional advisors and authorities. Lawyers, accountants, auditors, insurers, regulators, courts, law enforcement, and other parties when disclosure is reasonably necessary or legally required.
Corporate transaction parties. Potential or actual buyers, investors, lenders, successors, and advisors in a merger, financing, reorganization, or sale, subject to appropriate confidentiality and legal restrictions.
During the preceding 12 months, we have disclosed, as applicable, the categories described in Section 3 to service providers, contractors, Customers, and Customer-authorized integrations for the business purposes described in Section 5. The exact disclosures depend on the Services used.
7. Sale, Sharing, Targeted Advertising, and Sensitive Information
HepnerSync does not sell personal information for money. HepnerSync does not share personal information for cross-context behavioral advertising and does not use Customer Data for targeted advertising. We do not have actual knowledge that we sell or share personal information of anyone under 16.
We use sensitive personal information only as reasonably necessary to provide requested Services, secure accounts and systems, process transactions, comply with law, and perform other purposes permitted without a right to limit. We do not use sensitive personal information to infer characteristics for advertising. If our practices change, we will update this Policy and provide any required opt-out or limitation method before the new practice begins.
8. Cookies and Similar Technologies
We and our providers may use cookies, local storage, pixels, and similar technologies for authentication, session continuity, preferences, security, troubleshooting, performance, and analytics. Essential technologies are required for the Portal to function. Optional analytics or preference technologies may be controlled through available browser or site settings.
Because we do not sell or share personal information for cross-context behavioral advertising, a browser-based opt-out preference signal ordinarily will not change those practices. We will recognize and honor legally valid signals if we begin processing covered information in a way that requires an opt-out. Browser "Do Not Track" signals are not standardized, so the Services may not respond to them separately.
9. Customer Data Processing Commitments
When HepnerSync processes personal information in Customer Data as a service provider or processor, we will process it for the limited purposes of hosting and operating subscribed Modules; authenticating Users; executing configured workflows and integrations; producing reports; providing support, security, troubleshooting, and approved development; and complying with law. We will not sell or share it, use it outside the direct business relationship, or combine it with information from unrelated sources except as permitted by applicable privacy law or needed for security.
We require personnel and subprocessors with access to Customer Data to be bound by confidentiality and appropriate data-protection duties. We will provide reasonable assistance with valid individual-rights requests and legally required security or privacy assessments, taking into account the nature of processing and information available to us.
The Customer is responsible for telling us before a use would legally require HepnerSync to accept a specialized role, certification, or set of contractual terms beyond the standard Services. Applicable terms may be included in a Module Order or written addendum. A Customer's unilateral upload does not expand our contractual promises, although this Policy does not limit duties that applicable law imposes directly on either party.
10. Data Retention
We keep personal information only as long as reasonably necessary for the purpose collected, the Customer's instructions, the account and Module term, security and backup cycles, dispute resolution, and legal, tax, accounting, or regulatory requirements. The criteria below guide retention:
Account and identity records. Kept while the account is active and afterward as needed to document access, authority, contract acceptance, security, and legal obligations.
Orders, invoices, and payment records. Kept for the period required for tax, accounting, fraud prevention, collections, and contract enforcement.
Usage, diagnostic, and security logs. Kept for a limited period based on security risk, investigation needs, system performance, and provider log cycles.
Support and development records. Kept while work is open and afterward as needed to maintain the Customer configuration, document approvals, resolve defects, and improve support.
Customer Data. Kept according to the Customer agreement and instructions. The Terms generally provide a 30-day post-termination export window, after which Customer Data may be deleted from active systems, subject to legal holds and routine backup cycles.
Backups. Kept until overwritten or deleted through normal backup rotation. Backup data is isolated from ordinary use and retained only for recovery, security, or legal needs.
Marketing contacts. Kept until the person opts out, the information is no longer useful for the business relationship, or deletion is required.
We may keep deidentified or aggregated information that cannot reasonably be linked to a person. We will not attempt to reidentify it except to test whether deidentification remains effective or as allowed by law.
11. Security
We use commercially reasonable administrative, technical, and organizational safeguards appropriate to the Services and the types of information reasonably disclosed to us. Measures may include access controls, authentication, encryption in transit, environment separation, logging, monitoring, vendor controls, secure development practices, and incident response. Security depends partly on the Customer's data classification, configuration, Users, connected systems, and credentials. No method of transmission or storage is completely secure.
Users should use unique passwords, multifactor authentication when offered, secure devices, and least-privilege permissions, and should promptly report suspected unauthorized access to security@hepnercorp.com.
12. Privacy Rights
Depending on where a person lives and how the law applies, the person may have the right to request access to or confirmation of personal information; learn the categories, sources, purposes, and recipients; obtain a portable copy; correct inaccurate information; delete information; opt out of sale, sharing, targeted advertising, or certain profiling; limit certain uses of sensitive information; withdraw consent; and appeal a denied request. We will not discriminate against a person for exercising a privacy right.
12.1 Submit a request
For information HepnerSync controls, email privacy@hepnercorp.com with the subject "Privacy Request," or write to the address in Section 18. Describe the right requested, the relevant email or account, and the state or country of residence. For Customer Data, contact the Customer that collected the information; we will assist that Customer as required.
12.2 Verification
We will verify a request using information reasonably related to the request and the sensitivity of the data. We may ask a requester to confirm control of an email address, account, or other identifier. We will use verification information only to process the request. If we cannot verify identity or authority, we may limit or deny the request and explain why.
12.3 Authorized agents
An authorized agent may submit a request where allowed by law. We may require proof of signed authority and may verify identity directly with the individual, unless the agent has legally sufficient power of attorney.
12.4 Appeals
Where applicable law provides an appeal, reply to our decision or email the same address with the subject "Privacy Appeal" within 45 days. Explain why the decision should be reconsidered. We will respond within the time required by applicable law and provide information about contacting the appropriate regulator when required.
13. Children's Privacy
The Services are for businesses and are not directed to children under 13. We do not knowingly collect personal information directly from children under 13 through account signup. Customers must not invite a child to create a Portal account. If a Customer uses a Module to process information about minors, the Customer is responsible for lawful collection, notices, consents, access controls, and instructions to HepnerSync. Contact us if you believe a child submitted account information directly to HepnerSync.
14. United States Operation and International Data
HepnerSync operates from the United States and uses service providers that may process information in the United States or other countries. Those locations may have different privacy laws. A Customer that transfers personal information from another country is responsible for establishing a lawful transfer basis and requesting any required data-protection addendum before the transfer.
15. Third-Party Services
A Customer may connect or follow links to third-party services. Those providers control their own privacy and security practices. This Policy does not apply to information a third party receives outside its role as our service provider. The Customer should review the provider's terms and privacy notice before enabling an integration.
16. Changes to This Policy
We may update this Policy as the Services, vendors, laws, or practices change. We will post the updated Policy at the URL above and revise the effective date. We will provide reasonable notice through the Portal or account email before a material change takes effect. We will not make a material retroactive change to how previously collected personal information is used without additional notice or consent when required by law.
17. California and Other State Disclosures
For California residents, Section 3 describes the categories of personal information collected during the preceding 12 months, Section 4 describes sources, Section 5 describes business purposes, Section 6 describes categories of recipients and business-purpose disclosures, Section 7 describes sale, sharing, and sensitive information, Section 10 describes retention criteria, and Section 12 explains rights and request methods. We update these disclosures at least annually when the California Consumer Privacy Act applies.
We do not offer financial incentives or different prices in exchange for personal information. We do not sell or share personal information as those terms are defined by California law. We use and disclose sensitive personal information only for permitted purposes described in Section 7. Residents of other states may exercise the rights available under their applicable law through the same request process.
18. Contact Us
Hepner Corp, Attn: Privacy
3984 E Endeavor Drive, Appleton, Wisconsin 54915
Email: privacy@hepnercorp.com
Portal Terms of Service: https://www.hepnercorp.com/HS-TOS
Privacy Policy: https://www.hepnercorp.com/HS-PP