Back to home

Legal · Privacy

Privacy Policy

Last updated: July 17, 2026

This Privacy Policy explains how Pegalio, Inc. collects, uses, discloses, and safeguards personal data when you visit our websites, create an account, or use the Pegalio customer onboarding platform and related services.

Pegalio, Inc. (“Pegalio,” “we,” “us,” or “our”) provides a business-to-business software platform that helps companies onboard their customers — from closed-won to first value. This Privacy Policy applies to pegalio.com, our web dashboard, our customer portal, our APIs, and any other product, feature, or service that links to this policy (collectively, the “Services”). By using the Services, you acknowledge that you have read and understood this Privacy Policy.

1. Controller and processor roles

Pegalio plays two distinct roles depending on the data at issue. When we process personal data about visitors to our marketing site, prospects, and the account administrators and users of our workspaces, we act as a data controller. When our business customers upload or generate content within their workspace — including information about their own customers and onboarding participants — we act as a data processor that processes that content on our customer’s behalf and under their instructions, as set out in our Data Processing Addendum. In that scenario, our customer is the controller and is responsible for the lawful basis and notices provided to their own data subjects.

2. Information we collect

We collect the following categories of information:

  • Account and profile data. Name, work email address, workspace name, role, job title, profile image, authentication identifiers, and preferences you provide when you register or configure a workspace.
  • Customer content. Projects, tasks, files, forms, comments, messages, audit records, and other content that you or your workspace members submit to the Services. This content may include personal data about your own customers and onboarding participants.
  • Usage and log data. Actions taken in the Services, pages and features accessed, timestamps, referring pages, session identifiers, and diagnostic or performance telemetry.
  • Device and connection data. IP address, browser type and version, operating system, device identifiers, and language settings.
  • Cookies and similar technologies. Information collected through cookies, local storage, and comparable technologies as described in Section 9.
  • Communications. The content of messages you send to us, including support requests, sales inquiries, and survey responses.
  • Payment data. Billing contact details and subscription information. Card and bank details are collected and stored by our payment processor; we do not store full payment card numbers on our systems.

3. How we use information

We use personal data to:

  • provide, operate, maintain, and secure the Services;
  • authenticate users and administer workspaces, roles, and permissions;
  • process transactions and manage subscriptions, trials, and billing;
  • provide customer support and respond to your requests;
  • monitor, troubleshoot, and improve the Services, including developing new features and analyzing usage trends;
  • send administrative and transactional messages, and — where permitted — product updates and marketing communications you may opt out of at any time;
  • detect, investigate, and prevent fraud, abuse, security incidents, and other harmful or unlawful activity; and
  • comply with legal obligations and enforce our agreements.

4. Legal bases for processing

Where the EU or UK General Data Protection Regulation applies, we rely on the following legal bases: performance of a contract to provide the Services you request; our legitimate interests in operating, securing, and improving the Services (balanced against your rights); consent, where required, for certain marketing and non-essential cookies; and compliance with a legal obligation. Where we act as a processor, our customer is responsible for establishing the legal basis for the content they submit.

5. How we share information

We do not sell personal data. We disclose personal data only as described below:

  • Subprocessors and service providers. We engage vetted vendors to provide hosting, storage, email delivery, analytics, payment processing, and support tooling. These providers process data on our behalf under contractual confidentiality and security obligations. A current list is available on our Subprocessors page.
  • Within your workspace. Content is accessible to other members of your workspace according to the roles and permissions your administrators configure.
  • Legal and safety. We may disclose information where we believe in good faith that disclosure is required by law, regulation, legal process, or governmental request, or is necessary to protect the rights, property, or safety of Pegalio, our users, or the public.
  • Business transfers. If we are involved in a merger, acquisition, financing, reorganization, or sale of assets, personal data may be transferred as part of that transaction, subject to the commitments in this policy.

6. International data transfers

We operate globally, and personal data may be processed in countries other than the one in which it was collected, including the United States. When we transfer personal data from the European Economic Area, the United Kingdom, or Switzerland to countries that have not received an adequacy decision, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses and, where applicable, the UK International Data Transfer Addendum. Customers requiring EU or UK data residency may configure a self-hosted or region-scoped deployment where offered.

7. Data retention

We retain personal data for as long as your account is active and as needed to provide the Services. When a workspace is closed, we delete or de-identify customer content within a commercially reasonable period, typically within 30 days, unless a longer retention period is required to comply with legal obligations, resolve disputes, or enforce our agreements. Backups are retained on a rolling basis and are overwritten in the ordinary course of operations. Where we act as a processor, retention and deletion are governed by our customer’s instructions and the Data Processing Addendum.

8. Security

We maintain administrative, technical, and organizational measures designed to protect personal data against unauthorized access, disclosure, alteration, and destruction. These measures include encryption of data in transit and at rest, role-based access controls, least-privilege access, network isolation, logging and monitoring, and regular security reviews. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your account credentials confidential and for configuring workspace roles and permissions appropriately. Additional detail is available on our Security page.

9. Cookies and similar technologies

We use strictly necessary cookies to operate the Services (for example, to keep you signed in and to remember your locale), and, where permitted, functional and analytics cookies to understand usage and improve the Services. You can control non-essential cookies through your browser settings or any cookie controls we provide. Disabling strictly necessary cookies may prevent parts of the Services from functioning.

10. Your rights and choices

Depending on where you live, you may have rights to access, correct, delete, or port your personal data; to object to or restrict certain processing; and to withdraw consent. To exercise these rights, contact us at [email protected]. We will respond consistent with applicable law. If you are an end user of a Pegalio customer’s workspace, please direct your request to that customer, who acts as the controller of your data; we will assist them as their processor.

European Economic Area, United Kingdom, and Switzerland

You have the right to lodge a complaint with your local supervisory authority. We will not discriminate against you for exercising any of your rights.

California

Under the California Consumer Privacy Act, as amended by the California Privacy Rights Act, California residents have the right to know, delete, correct, and opt out of the sale or sharing of personal information, and the right to limit the use of sensitive personal information. We do not sell or share personal information as those terms are defined under California law. To exercise your rights, contact us at [email protected].

11. Children’s privacy

The Services are intended for businesses and are not directed to children under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will take appropriate steps to delete it.

12. Third-party links and services

The Services may link to or integrate with third-party websites and services that we do not control. This Privacy Policy does not apply to those third parties, and we encourage you to review their privacy practices.

13. Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, provide additional notice through the Services or by email. Your continued use of the Services after an update takes effect constitutes acceptance of the revised policy.

14. Contact us

If you have questions about this Privacy Policy or our privacy practices, contact us at [email protected] or by mail at Pegalio, Inc., San Francisco, California, United States. For matters where we act as a processor, please also see our Data Processing Addendum and Terms of Service.

Privacy Policy | Pegalio