InspireIP Privacy Policy
1. Introductions and Definitions
1.1 Introduction
1.2 Definitions
For the purposes of this Privacy Policy:
- Personal Data: Information that identifies or can identify an individual.
- Customer Data: All data, including invention disclosures, IP-related content, and files uploaded by customers to the Service.
- Usage Data: Information automatically collected about how the Service is used.
- Controller: The entity that determines the purposes and means of processing Personal Data (typically your organization).
- Processor: The entity that processes Personal Data on behalf of the Controller (InspireIP acts as Processor for Customer Data).
- Service: The InspireIP platform, including web, mobile, and API access.
2. Information We Collect
2.1 Information You Provide
- Account Information: Name, email address, job title, organization name, phone number
- Customer Data: Invention disclosures, patent documentation, innovation challenges, comments, and any content you upload to the Service
- Payment Information: Billing address and payment method details (processed through third-party payment processors; we do not store complete credit card numbers)
- Communications: Messages, support requests, and feedback you send to us
2.2 Information Collected Automatically
- Device Information: IP address, browser type, operating system, device identifiers
- Usage Information: Pages visited, features used, time spent on pages, click patterns, search queries within the Service
- Cookies and Tracking Technologies: Session identifiers, authentication tokens, preference settings
2.3 Information from Third Parties
- Single Sign-On (SSO): If you authenticate via third-party services (e.g., Microsoft, Google), we receive basic profile information
- Integration Partners: Data from systems you connect to InspireIP (e.g., docketing systems, collaboration tools)
3. How We Use Your Information
3.1 Service Delivery
- Provide, maintain, and improve the Service
- Process invention disclosures and IP management workflows
- Enable collaboration between inventors, reviewers, and IP counsel
- Generate analytics and insights within your organization’s account
3.2 AI-Powered Features
We use artificial intelligence to enhance the Service, including:
- PQAI (Prior Art Search): Our proprietary, non-generative AI analyzes patent databases to identify prior art. PQAI operates on private servers and does NOT use your Customer Data to train AI models.
- Inventor Assist: Powered by ChatGPT Enterprise API, this feature guides users through structured disclosure development. Under our ChatGPT Enterprise agreement:
- Your inputs and outputs are NOT used to train OpenAI models
- Data is encrypted in transit and at rest
- OpenAI does not retain your data beyond the session
3.3 Communications
- Send service updates, security alerts, and administrative messages
- Respond to inquiries and support requests
- Send marketing communications (you may opt out at any time)
3.4 Security and Compliance
- Detect and prevent fraud, abuse, and security incidents
- Comply with legal obligations and enforce our Terms of Service
- Conduct audits and maintain SOC 2 Type II compliance
3.5 Analytics and Improvement
- Analyze usage patterns to improve features and user experience
- Conduct aggregated, anonymized research (never using identifiable Customer Data)
4. How We Share Your Information
4.1 We Do NOT Sell Your Data
4.2 Service Providers
We share information with trusted third-party vendors who assist in operating our Service:
- Cloud Infrastructure: AWS (hosting, storage)
- Payment Processing: Stripe (payment transactions)
- Communication Tools: Email service providers for transactional emails
- Analytics: Usage analytics platforms (with anonymized/aggregated data only)
All service providers are contractually obligated to protect your data and may only use it to provide services to InspireIP.
4.3 Legal Requirements
- Comply with valid subpoenas, court orders, or legal obligations
- Protect InspireIP’s rights, property, or safety
- Investigate fraud or security incidents
- Enforce our Terms of Service
4.4 Business Transfers
4.5 With Your Consent
5. Data Security
5.1 Security Measures
We implement industry-standard security controls, including:
- Encryption: Data encrypted in transit (TLS 1.2+) and at rest (AES-256)
- Access Controls: Role-based access, multi-factor authentication (MFA)
- SOC 2 Type II Compliance: Independently audited security controls
- Vulnerability Assessments: Regular penetration testing (VAPT certification)
- Employee Training: Security awareness and data handling protocols
5.2 Your Responsibility
5.3 No Absolute Guarantee
6. Data Retention
6.1 Customer Data
- We retain Customer Data for as long as your account is active or as needed to provide the Service
- Upon account termination, we delete or anonymize Customer Data within 90 days, unless:
- Required by law to retain longer
- Needed to resolve disputes or enforce agreements
- You request an extended retention period
6.2 Usage Data and Logs
- Usage Data is retained for up to 24 months for security and analytics
- System logs are retained for up to 12 months
6.3 Backups
- Backup copies may persist for up to 30 days after deletion for disaster recovery purposes
7. Your Privacy Rights
7.1 Access and Portability
7.2 Correction and Deletion
7.3 Marketing Opt-Out
7.4 Cookies and Tracking Technologies
What Are Cookies?
Cookies are small text files stored on your device when you visit our website or use our Service. We also use similar technologies like web beacons, local storage, and session identifiers (collectively referred to as “cookies” in this section).
Types of Cookies We Use:
a) Strictly Necessary Cookies
- Purpose: Essential for the Service to function (authentication, security, load balancing)
- Examples: Session tokens, CSRF protection, login state
- Duration: Session-based or up to 12 months
- Opt-Out: Cannot be disabled without losing core functionality
- Legal Basis (GDPR): Necessary to provide the Service you requested
b) Analytics and Performance Cookies
Google Analytics
- Purpose: Understand how visitors use our Service to improve user experience
- Cookies Set:
_ga,_gid,_gat - Duration: Up to 24 months
- Data Collected: Page views, session duration, traffic sources, device type, anonymized IP addresses
- Privacy Measures: IP anonymization enabled; no data shared with Google for advertising
- Privacy Policy: Google Analytics Privacy
Microsoft Clarity
- Purpose: Session recording and heatmaps to understand user behavior and improve UX
- Cookies Set:
_clck,_clsk,CLID,ANONCHK,MR,MUID,SM - Duration: Up to 13 months
- Data Collected: Mouse movements, clicks, scroll patterns (with sensitive data automatically masked)
- Privacy Measures: Form inputs, payment info, and PII are automatically masked
- Privacy Policy: Microsoft Clarity Privacy
HubSpot (CRM and Chat)
- Purpose: Manage chat widget, remember form inputs, track support interactions
- Cookies Set:
__hssc,__hssrc,__hstc,hubspotutk,messagesUtk - Duration: Up to 13 months
- Data Collected: Chat history, form submissions, support context
- Privacy Policy: HubSpot Privacy
Legal Basis (GDPR): Legitimate interest in improving our Service and providing support. You have the right to object.
c) Functionality Cookies
- Purpose: Remember your preferences (language, UI settings, “don’t show again” flags)
- Duration: Up to 12 months
- Legal Basis (GDPR): Legitimate interest in providing a personalized experience
d) Advertising/Marketing Cookies
- Current Status: We do NOT use advertising or cross-site tracking cookies
- Future Use: If introduced, we will update this policy and obtain explicit consent before setting such cookies
Managing Your Cookie Preferences:
Cookie Consent Banner
When you first visit our website, you can choose:
- Accept All: Enable all cookies
- Reject Non-Essential: Allow only strictly necessary cookies
- Cookie Settings: Customize your preferences by category
You can change your preferences anytime by clicking “Cookie Settings” in the website footer.
Browser Settings
You can control cookies through your browser:
- Chrome: Settings → Privacy and security → Cookies and other site data
- Firefox: Settings → Privacy & Security → Cookies and Site Data
- Safari: Preferences → Privacy → Cookies
- Edge: Settings → Cookies and site permissions
Warning: Blocking all cookies may prevent essential features from working.
Opt-Out Tools
- Google Analytics: Install the Google Analytics Opt-out Add-on
- Microsoft Clarity: Enable Do Not Track (DNT) in your browser settings (Clarity honors DNT signals)
- HubSpot: Email [email protected] to opt out while still using the Service
Do Not Track (DNT)
We honor DNT signals for analytics cookies. Strictly necessary cookies will still be set.
Third-Party Cookies:
Some cookies are set by third parties (Google, Microsoft, HubSpot). We do not control these directly. We have Data Processing Agreements (DPAs) with each vendor to ensure GDPR compliance. Refer to their privacy policies (linked above) for details on their data practices.
Mobile Apps:
Our mobile apps use similar tracking:
- Session tokens for authentication
- Firebase Analytics (Google) for usage tracking
- Crash reporting to identify bugs
Mobile Privacy Controls:
- iOS: Settings → Privacy → Tracking → Toggle off for InspireIP
- Android: Settings → Google → Ads → Opt out of Ads Personalization
Cookie Lifespan:
- Session cookies: Deleted when browser closes
- Authentication cookies: 30 days (or until logout)
- Analytics cookies: Up to 24 months (Google Analytics, Microsoft Clarity, HubSpot)
- Preference cookies: Up to 12 months
You can delete cookies manually at any time through your browser settings.
8. Regional Privacy Rights
8.1 European Economic Area (EEA), UK, and Switzerland (GDPR)
If you are located in the EEA, UK, or Switzerland, you have additional rights under the General Data Protection Regulation (GDPR):
Legal Basis for Processing:
- Contract Performance: Processing necessary to provide the Service
- Legitimate Interests: Improving the Service, security, and fraud prevention
- Consent: Marketing communications (you may withdraw consent anytime)
- Legal Compliance: Responding to legal requests
Your GDPR Rights:
- Right to Access: Request a copy of your Personal Data
- Right to Rectification: Correct inaccurate data
- Right to Erasure: Request deletion (“right to be forgotten”)
- Right to Restriction: Limit how we use your data
- Right to Data Portability: Receive your data in a machine-readable format
- Right to Object: Object to processing based on legitimate interests
- Right to Withdraw Consent: For consent-based processing
Exercising Your Rights:
Contact us at [email protected]. We will respond within 30 days.
Data Transfers:
InspireIP is based in the United States. We transfer data to the U.S. using:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Additional safeguards as required by law
Supervisory Authority:
You have the right to lodge a complaint with your local data protection authority.
8.2 California Residents (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) provide specific rights:
Categories of Personal Information We Collect:
- Identifiers (name, email, IP address)
- Commercial information (subscription details)
- Internet activity (usage data)
- Professional information (job title, organization)
How We Use Personal Information: See Section 3 (“How We Use Your Information”)
Categories of Third Parties We Share With: See Section 4 (“How We Share Your Information”)
Your CCPA/CPRA Rights:
- Right to Know: Request details about data we collect, use, and share
- Right to Delete: Request deletion of your Personal Data
- Right to Correct: Request correction of inaccurate data
- Right to Opt-Out: We do not “sell” or “share” Personal Data for cross-context behavioral advertising
- Right to Limit Sensitive Data: We do not use sensitive personal information for purposes beyond providing the Service
- Right to Non-Discrimination: We will not discriminate against you for exercising your rights
Exercising Your Rights:
- Email: [email protected]
- Subject line: “California Privacy Rights Request”
- We will verify your identity and respond within 45 days
Shine the Light: California residents can request information about data shared with third parties for direct marketing (we do not engage in such sharing).
8.3 Other U.S. States
9. Children’s Privacy
10. International Users
11. Third-Party Links and Integrations
12. Changes to This Privacy Policy
- Send email notification to registered users
- Display a prominent notice on the Service
13. Contact Us
For questions, concerns, or to exercise your privacy rights:
InspireIP Privacy Team
Email: [email protected]
Address: Sam Zellner Services LLC., dba InspireIP
2350 Fenhurst Place, Dunwoody, GA 30338, United States
Phone: +1 (404) 424-4041
Response Time: We aim to respond within 5 business days for general inquiries and within the legally required timeframes for rights requests (typically 30-45 days).
14. Data Processing Addendum (DPA)
© 2025 Sam Zellner Services LLC., dba InspireIP. All rights reserved.
