The Progress Lab Join the waitlist
Menu

This Privacy Policy explains how ProgressLab collects, uses, discloses, and protects information in connection with our website, platform, applications, agents, model-selection tools, data-enrichment tools, entity-resolution tools, public-source search features, and related services.

Our processing of data uploaded or submitted by Customers may also be governed by our Terms of Use, beta user agreements, Customer agreements, data processing addenda, and other written agreements.

1. Overview

Company provides an AI-enabled platform that allows users to engage with agents and models to support workflow automation, research, entity resolution, data matching, data enrichment, data analysis, public-source research, donor or supporter identification, and related activities.

Customers may upload files, datasets, lists, voter files, contributor lists, donor information, fundraising information, campaign information, cause-related information, and other information to the platform. The platform may use Customer-uploaded data, Customer instructions, Company-approved AI models within Company’s AWS-hosted environment, data-enrichment methods, entity-resolution methods, and searches of publicly available sources to generate outputs.

In many cases, we process Customer Data on behalf of and at the direction of our Customers, and our Customers are responsible for determining what data to submit to the Services and how to use Enriched Data and Outputs.

Company is based in the United States, and the Services are hosted and operated within Amazon Web Services (“AWS”) infrastructure located in the United States. All Customer Data is processed within Company’s AWS-hosted environment and is not transmitted to other external AI model providers. All AI functionality made available through the Services is provided through Company-approved infrastructure and contractual controls designed to prevent model training on Customer Data. Company regularly evaluates AI models and infrastructure providers based in part on their data-handling practices and may decline to offer models or features that do not meet Company’s customer-data protection requirements.

2. Information We Collect

We may collect the following categories of information.

2.1 Account and Contact Information

We may collect names, email addresses, phone numbers, organization names, job titles, billing information, account credentials, and related account information.

2.2 Customer Data

Customers and authorized users may upload or submit files, lists, datasets, prompts, queries, documents, voter files, contributor lists, donor information, fundraising information, campaign information, civic participation information, cause-related information, demographic information, contact information, issue-interest information, and other content to the Services.

Depending on the Customer’s data and use case, Customer Data may include Personal Information, sensitive information, political or civic information, donor or contributor information, voter information, demographic information, and information subject to special legal, contractual, or licensing restrictions.

2.3 Enriched Data, Inferences, and Outputs

The Services may generate enriched data, matched records, resolved entities, appended attributes, classifications, scores, rankings, segments, inferences, recommendations, donor-prospect lists, supporter-prospect lists, research results, summaries, and other outputs based on Customer Data, public sources, AI functionality made available through the Services, and Customer instructions.

2.4 Usage and Technical Information

We may collect information about how users interact with the Services, including log data, device information, browser type, IP address, access times, pages or features used, model selections, agent interactions, enrichment requests, entity-resolution jobs, public-source searches, error logs, performance information, security logs, and similar technical information.

2.5 Publicly Available Information

At a Customer’s direction, the Services may search, retrieve, summarize, match, append, classify, or analyze information from publicly available sources.

2.6 Communications

We may collect information when you contact us, request support, provide feedback, participate in a beta program, or otherwise communicate with us.

3. No Cookies

Our website and Services are designed not to use cookies.

We may, however, collect technical information necessary to provide, secure, monitor, and improve the Services, such as server logs, authentication records, security logs, system logs, usage records, and similar operational information.

4. How We Use Information

We may use information to:

5. Customer-Directed Processing

Company provides a Customer-directed software platform. Customers decide what Customer Data to upload, what workflows to run, what enrichment or entity-resolution tasks to initiate, what models or features to use, and how to review, export, disclose, or use Enriched Data and Output.

We process Customer Data, Enriched Data, and Outputs to provide the Services to the applicable Customer and in accordance with our Terms of Use, Customer agreements, and applicable law.

Customers are responsible for determining whether and how they may lawfully export, disclose, or use Customer Data, Enriched Data, and Outputs outside the Services.

6. AI Model Use

Unless Customer expressly agrees in writing, Company does not use Customer Data, Enriched Data, Outputs, prompts, queries, or related information to train, fine-tune, evaluate, or improve any AI model, whether operated by Company or a third party. All Customer Data is processed by Company within its AWS-hosted environment in the United States and is not transmitted to other third-party AI service providers. All AI functionality made available through the Services is provided through Company-approved infrastructure and contractual controls designed to prevent model training on Customer Data.

7. Data Enrichment, Entity Resolution, and Inferences

The Services may help Customers match, append, enrich, classify, score, infer from, rank, segment, normalize, deduplicate, or resolve information about individuals or entities.

Company currently does not purchase, license, or maintain commercial datasets for use in enriching or otherwise processing Customer Data. If Company introduces licensed third-party datasets or enrichment sources in the future, Company will notify Customers of the terms pursuant to which such datasets and sources will be made available.

Enrichment performed through the Services is currently generated from (a) Customer Data, including data that the Customer has lawfully purchased or licensed from third parties and uploaded to the Services, (b) publicly available information retrieved at the Customer’s direction, and (c) inferences, classifications, scores, and other derivations generated by the Services from the foregoing.

For example, the Services may identify potential matches between records, append publicly available information, generate inferred attributes, classify records into segments, score potential donor or supporter interest, or recommend additional individuals or entities for Customer review.

These processes are performed to provide the Services to the applicable Customer and at the Customer’s direction.

Enriched Data and Outputs may be probabilistic, estimated, incomplete, outdated, duplicative, or incorrect. Customers are responsible for reviewing, validating, and lawfully using Enriched Data and Outputs.

Enrichment results and inferences are generated for the applicable Customer’s use and should not be treated as verified facts without Customer review.

Where the Services display model bias scores, environmental impact scores, or other comparative information, such information is provided for informational purposes only and may be based on available research, third-party information, estimates, model documentation, or Company methodology. Company does not represent that such scores are complete, definitive, universally accepted, free from error, or suitable for any particular decision.

8. No Sale of Customer Data; No Cross-Customer Individual Profiles

We process Customer Data solely to provide the Services to the applicable Customer.

We do not sell Customer Data, Enriched Data, or Outputs.

Unless expressly stated in a written agreement, we do not share Customer Data, Enriched Data, or Outputs for cross-context behavioral advertising.

We do not use Customer Data, Enriched Data, or Outputs from one Customer to build, sell, rent, license, disclose, transfer, or otherwise make available individual-level profiles, donor lists, voter lists, supporter lists, prospect lists, political-affinity lists, issue-interest lists, or other Personal Information to another Customer or third party.

We do not combine identifiable Customer Data, Enriched Data, or Outputs from multiple Customers into a shared, cross-Customer database of individual-level records for sale, licensing, disclosure, or other independent commercial use.

The Services may allow Customers to create and, at the Customer’s sole discretion, share with other Customers configurations, prompt templates, workflows, agent definitions, integrations, or other components that the Customer has created using the Services (“Skills” or “Plugins”). Any such sharing is initiated by, and at the direction of, the sharing Customer. Sharing of a Skill or Plugin does not, and we will not use the sharing functionality to, transfer, disclose, or otherwise make available to any other Customer or third party any Customer Data, Enriched Data, or Outputs. Only the Skill or Plugin itself is shared.

9. Public-Source Research

At a Customer’s direction, the Services may search, retrieve, summarize, match, append, analyze, classify, or otherwise process publicly available information.

Public-source information retrieved or generated for a Customer is provided for that Customer’s use within the Services and is not used by Company to create a Company-owned data marketplace or cross-Customer database of individual-level profiles.

10. How We Disclose Information

We may disclose information to:

We may disclose aggregated or de-identified information that does not reasonably identify an individual or Customer, subject to applicable law and contractual commitments.

11. AWS Infrastructure & Enterprise Search Providers

Company utilizes AWS as its cloud infrastructure provider. Customer Data is processed within Company’s AWS-hosted environment located within the United States.

Certain Customer-directed search features may utilize enterprise search providers acting on Company’s behalf. Company configures such services to suppress or minimize retention of Customer queries and content wherever commercially reasonable and available, while permitting limited operational metadata retention necessary for service administration, security, and troubleshooting.

12. Customer Responsibilities

Customers are responsible for determining whether they may lawfully collect, upload, process, analyze, combine, enrich, match, infer from, disclose, export, and use Customer Data, Enriched Data, and Outputs through the Services.

Customers are responsible for providing required privacy notices, obtaining required consents or authorizations, honoring individual rights requests, complying with voter-file and contributor-list restrictions, and complying with applicable laws governing their use of Customer Data, Enriched Data, and Outputs.

Customers must not upload Personal Information unless they have the legal right to do so and have determined that use of the Services is appropriate for that information.

13. Company’s Role; Service-Provider Posture

Company provides a Customer-directed software and data-enrichment platform. In many cases, Company processes Customer Data on behalf of and at the direction of its Customers. In those contexts, Company acts as a service provider or processor (as those terms are defined under applicable privacy law), and the Customer is the business or controller that determines what data to submit and how to use Enriched Data and Outputs.

As a service provider, Company processes Customer Data to provide the Services to the applicable Customer. Company does not sell, rent, license, disclose, or otherwise make available Customer Data, Enriched Data, or Outputs to third parties for their own independent use, and does not use Customer Data received from one Customer to build, sell, license, or disclose individual-level profiles or Personal Information to another Customer or third party.

Customers remain responsible for evaluating whether their own collection, upload, processing, enrichment, export, disclosure, or downstream use of data subjects them to data broker, privacy, consumer protection, election, campaign finance, voter-file, contributor-list, or similar laws. Company does not determine, and is not responsible for, whether a Customer’s upstream data collection practices or downstream use of Enriched Data and Outputs comply with applicable law.

Where Company collects Personal Information in its own right, such as account registration and contact information, usage data, and billing information, Company acts as a business or controller with respect to that information and processes it as described in this Privacy Policy.

14. Aggregated and De-Identified Information

We may use aggregated or de-identified information to operate, secure, analyze, and improve the Services, provided such information does not identify a Customer, authorized user, or individual contained in Customer Data and is not used to build, sell, license, disclose, or make available individual-level profiles or Personal Information.

15. Security

We use commercially reasonable administrative, technical, and organizational safeguards designed to protect information against unauthorized access, use, disclosure, alteration, or destruction.

We offer Security Tiers 2, 3, and 4, as described in Company’s Security Documentation. The applicable Security Tier depends on the Customer’s selected plan, implementation, cloud environment, model selection, key-management settings, and applicable agreement.

Our supported configurations may include Customer-managed security, Customer-owned security, Customer-managed encryption keys, Customer-owned encryption keys, private model environments, Customer-directed key rotation, and Customer-directed platform access.

Some security controls require Customer participation, configuration, key management, access control, and ongoing maintenance.

Customers are responsible for selecting a supported security configuration appropriate for the sensitivity, volume, legal restrictions, and intended use of the data they submit to the Services.

If a Customer uses Customer-managed or Customer-owned encryption keys, the Customer is responsible for managing those keys. Loss, misconfiguration, revocation, expiration, or disabling of Customer-managed or Customer-owned keys may make Customer Data, Enriched Data, or Outputs unavailable or unrecoverable.

No security measure is perfect, and we cannot guarantee absolute security.

16. Customer Data Retention

Company retains Customer Data only as long as necessary to provide the Services, honor Customer-controlled retention settings, maintain security, investigate incidents, comply with legal obligations, and operate the platform. Company does not retain Customer Data for model training or unrelated commercial purposes.

Company provides Customer-controlled retention of Customer Data, Enriched Data, and Outputs. Customers may access, export, and delete Customer Data at any time through available platform controls. Customers should export or preserve Customer Data, Enriched Data, and Outputs before terminating their account or requesting deletion if they need to retain such information.

17. U.S.-Based Processing

Company is based in the United States and its Services are hosted and operated primarily through AWS infrastructure located in the United States. Customer Data remains within the United States unless otherwise agreed in writing or required by law.

18. Privacy Rights

Depending on where individuals reside, they may have rights regarding their Personal Information, such as rights to access, delete, correct, or opt out of certain uses or disclosures of Personal Information.

Because we often process Customer Data on behalf of Customers, individuals seeking to exercise rights regarding information contained in Customer Data will generally need to contact the relevant Customer directly, as Company processes such information on behalf of and at the direction of its Customers.

Where required by law or contract, we will assist Customers in responding to applicable privacy rights requests.

19. California Notice

This section applies to California residents to the extent the California Consumer Privacy Act, as amended, applies to our processing of their Personal Information.

We may collect the following categories of Personal Information:

We use sensitive Personal Information only for the purposes disclosed in this Privacy Policy, including providing the Services, processing Customer Data at Customer direction, performing enrichment and entity resolution, generating Enriched Data and Outputs, securing the Services, communicating with users, and complying with legal obligations. We do not use sensitive Personal Information for purposes that would require us to offer a right to limit use or disclosure under California Civil Code Section 1798.121, because our use of sensitive Personal Information is limited to the purposes for which it was collected or as otherwise permitted by law. If our practices change, we will update this Privacy Policy and provide any required opt-out mechanism.

Customers are responsible for determining whether Customer Data they submit to the Services contains sensitive Personal Information, and for ensuring that collection, upload, processing, and use of such information complies with applicable law, including applicable consent, notice, and data-use restrictions. Customers should not submit sensitive Personal Information unless they have a lawful basis to do so and have determined that use of the Services is appropriate for that information.

We collect and use Personal Information for the purposes described in this Privacy Policy, including providing the Services, processing Customer Data at Customer direction, performing entity resolution and data enrichment, generating Enriched Data and Outputs, securing the Services, communicating with users, and complying with legal obligations.

Unless expressly stated in a written agreement, we do not sell Personal Information contained in Customer Data, Enriched Data, or Outputs, and we do not share such Personal Information for cross-context behavioral advertising.

We also do not use Customer Data, Enriched Data, or Outputs from one Customer to build, sell, license, disclose, or make available individual-level profiles or Personal Information to another Customer or third party.

We do not knowingly sell or share Personal Information of individuals under 16 (the minimum age for opt-in consent to sale or sharing under the CCPA).

California residents may have rights to know, access, delete, correct, opt out of sale or sharing, limit certain uses of sensitive Personal Information, and not be discriminated against for exercising privacy rights.

20. Children

The Services are not directed to children under 13, and we do not knowingly collect Personal Information from children.

Customers should not submit information about individuals under 13 through the Services. If Customer uploads data that may include information about minors, Customer is solely responsible for ensuring that such upload and processing comply with applicable law, including COPPA.

21. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. The updated version will be posted on our website or otherwise made available. The “Last Updated” date indicates when this Privacy Policy was last revised.

22. Contact Us

For questions about this Privacy Policy, contact us at:

ProgressLab, PBC.
345 W Washington Ave
Ste 301 #3111
Madison, WI 53703
United States
hello@progresslab.ai