Privacy Policy
Effective 2026-08-20. Version 1.2.0.
This policy explains how CompanyWRX, LLC ("we," "us") handles personal information across every service we operate, including CompanyWRX, HireWRX, RevuNow, FieldIQ, HelmVox, BridgeThru, JourneyMan and MenuQR.
1. Two different roles — this matters
When we act for ourselves (a "controller"). Information about you, our customer — your account, your billing, your support tickets, how you use our websites. This policy governs it.
When we act for our customer (a "processor"). Information our business customers put into a Service about their customers, candidates, employees or households. We process that only on our customer's instructions. We are not the right party to ask about it.
If you received a text message, an interview invitation, a service call or a review request and want to know why: the business that contacted you controls that data, not us. Ask them. We will help you identify them — email privacy@companywrx.com with the message you received and we will tell you which business sent it and pass your request along.
2. What we collect
You give us:
- account and profile details — name, business name, email, phone, job title;
- billing details — billing address and the last four digits and card type of your payment method (full card numbers go directly to Stripe; we never see or store them);
- content you submit — Customer Data, files, messages, recordings, and anything you type into a Service; and
- support correspondence.
We collect automatically:
- log and device data — IP address, browser and device type, operating system, timestamps, pages and features used, referring URL;
- usage and diagnostics — feature usage counts, performance metrics, error reports; and
- cookies and similar technologies (Section 8).
We receive from others:
- payment and subscription status from Stripe;
- message delivery status from Twilio and email delivery status from Resend;
- authentication data if you sign in through a third-party identity provider; and
- data from integrations you connect.
Legal-acceptance records. When you accept our Terms we record your account and user identifier, the document keys and versions, a cryptographic hash of the exact text shown, the timestamp, your IP address and user agent. We keep these for as long as your account exists and for six years after, because they are the evidence of the contract between us.
3. Why we use it, and our legal bases
| Purpose | Legal basis (GDPR/UK GDPR) |
|---|---|
| Provide, operate and support the Services | Contract |
| Bill you and collect payment | Contract; legal obligation |
| Authenticate you and secure accounts | Contract; legitimate interests |
| Prevent fraud, abuse and security incidents | Legitimate interests; legal obligation |
| Diagnose problems and improve the Services | Legitimate interests |
| Send service, security and billing notices | Contract; legitimate interests |
| Send marketing about our products | Consent, or legitimate interests where permitted |
| Comply with law and respond to lawful requests | Legal obligation |
| Establish, exercise or defend legal claims | Legitimate interests |
We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined by the CCPA/CPRA and comparable state laws.
4. AI processing
Some Services send content to AI model providers (Anthropic, OpenAI, Voyage AI) to generate summaries, transcripts, scores, recommendations and search results. Our agreements with those providers prohibit them from using your content to train their models. See Subprocessors.
Output can be wrong. Section 12 of the Terms explains what that means for you and requires a human to review anything that affects a person.
5. Who we share it with
- Subprocessors — the service providers listed at Subprocessors, each under contract.
- Your own organisation — other Authorized Users and administrators of your account can see activity within it. An account administrator can see what users of that account do in the Service.
- At your direction — third-party integrations you connect.
- Professional advisors — lawyers, accountants and auditors, under confidentiality.
- Legal and safety — where required by law, subpoena or court order, or where we reasonably believe disclosure is necessary to protect rights, safety, or to investigate fraud or a security incident. Where we are legally permitted to tell you about a request for your data, we will.
- Business transfer — in a merger, acquisition, financing or sale of assets, subject to this policy continuing to apply.
6. How long we keep it
| Data | Retention |
|---|---|
| Account and profile | While your account is active |
| Customer Data | While active; exportable for 90 days after termination, then deleted |
| Billing and tax records | 7 years (tax and accounting law) |
| Legal-acceptance records | Life of account + 6 years |
| Security and access logs | 12 months |
| Support correspondence | 3 years |
| Encrypted backups | Until they expire on their normal rotation |
7. Your rights
Depending on where you live you may have the right to access, correct, delete, port, restrict or object to the processing of your personal information, to withdraw consent, and to not be discriminated against for exercising a right.
How to exercise them: email privacy@companywrx.com. We will verify your identity — usually by confirming control of the account email — and respond within 45 days (extendable once by 45 days) or within the shorter period your law requires. Using a right costs nothing and changes nothing about your service or pricing.
Authorized agents may submit a request on your behalf with written proof of authorization.
Appeals. If we refuse a request, you may appeal by replying to our decision with the word "Appeal." We will respond within 45 days with our reasons. If we still refuse, you may complain to your state attorney general or supervisory authority.
If we process your information for one of our business customers, we will refer your request to that customer, who decides how to respond. See the callout in Section 1.
8. Cookies
We use cookies that are strictly necessary (session, authentication, security, load balancing) and functional (remembering your preferences). We use limited first-party analytics to understand feature usage.
We do not use third-party advertising or cross-site tracking cookies. Strictly necessary cookies cannot be disabled without breaking sign-in. You can control the rest through your browser. We honour Global Privacy Control signals as an opt-out of sale/sharing where applicable law requires.
9. Security
We use encryption in transit and at rest, least-privilege access controls, per-service isolated system accounts, network filtering, automated intrusion monitoring, and routine patching. We notify affected customers of a qualifying security incident within 72 hours of becoming aware of it.
No system is perfectly secure. Use a strong unique password, enable multi-factor authentication, and remove users who leave.
10. Children
The Services governed by this policy are not directed to children under 18 and we do not knowingly collect personal information from them. If you believe a child has provided us information, email privacy@companywrx.com and we will delete it.
KittyKlash is different. It is intended for children and is governed by its own children's privacy notice and terms, not by this policy.
11. International transfers
We operate in the United States and personal information is processed there. If you are in the European Economic Area, the United Kingdom or Switzerland, transfers rely on the European Commission's Standard Contractual Clauses together with supplementary measures, as set out in our Data Processing Addendum. Request a copy of the safeguards from privacy@companywrx.com.
12. State-specific disclosures
California (CCPA/CPRA). In the last 12 months we collected the categories in Section 2 — identifiers, commercial information, internet activity, geolocation (coarse, from IP), audio where a Service records it, professional or employment information, and inferences drawn from AI features — for the purposes in Section 3, from the sources in Section 2, and disclosed them for business purposes to the recipients in Section 5. We have not sold personal information or shared it for cross-context behavioural advertising in the last 12 months. You have the rights in Section 7, including the right to limit use of sensitive personal information — though we do not use sensitive personal information for any purpose requiring that right.
Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana and other states with comprehensive privacy laws: you have the rights in Section 7, including appeal (Section 7). We do not process personal information for targeted advertising or profiling with legal or similarly significant effects on our own behalf.
Nevada. We do not sell covered information; you may still submit a request to privacy@companywrx.com.
13. Changes
We will post any change here with a new version number and effective date. For a material change we will give at least 30 days' notice by email or in-product notice.
14. Contact
CompanyWRX, LLC Privacy: privacy@companywrx.com Security: security@companywrx.com Legal: legal@companywrx.com
Version 1.2.0 — effective 2026-08-20.
