Privacy Policy
Overview
This Privacy Policy explains how SizeUpIQ processes information when you use SizeUpIQ. It applies to the SizeUpIQ website, accounts, organizations, training workflows, Scenario Library, Scenario Exchange, Scenario Builder, assessments, reporting, notifications, support features, integrations, and other services described here.
This Policy describes SizeUpIQ's data practices. Additional responsibilities concerning use of the service, uploaded content, training reliance, cybersecurity risks, and limitations of liability are addressed in the SizeUpIQ Terms of Use.
Information you provide
We process information you provide to establish and manage an account, including your name, email address, authentication and security settings, organization memberships, roles, invitations, and profile information.
We also process information you or your organization provide through the service, including scenarios, media, assessments, answers, reviews, assignments, group information, ratings, support requests, feedback, and other user-created content.
You and your organization are responsible for determining whether information submitted to SizeUpIQ may lawfully be collected, uploaded, shared, or processed.
Do not provide highly sensitive or specially regulated information that is unnecessary for the intended SizeUpIQ workflow. Unless SizeUpIQ has expressly agreed in writing that a service is intended for such information, users should not upload protected health information, patient-identifying information, Social Security numbers, financial credentials, authentication secrets, confidential investigative material, or other data subject to specialized handling requirements.
Uploaded media and user content
SizeUpIQ may process photographs, video, audio, documents, illustrations, and other media you upload. Uploading content does not by itself transfer your ownership of that content to SizeUpIQ. Ownership, licenses, intellectual-property responsibilities, and copyright-reporting procedures are addressed in the Terms of Use.
SizeUpIQ generally does not independently verify the ownership, copyright status, releases, permissions, provenance, or legality of user-uploaded media. Users and organizations are responsible for ensuring that they have authority to upload and process the content they provide and that they do not disclose personal, confidential, or restricted information without authorization.
Scenario Exchange and shared content
When you intentionally publish a scenario or related content for sharing through Scenario Exchange, information included in that content may become visible to other users as provided by the sharing functionality of the service.
Shared content may also be copied into another user's or organization's workspace where the service provides that functionality. Do not include personal information, private incident information, confidential agency information, patient or victim information, restricted operational material, or other information that should not be shared with the intended Scenario Exchange audience.
Changing or removing the availability of the original shared scenario may not remove copies previously created by other authorized users through the service.
Training and activity information
SizeUpIQ records information necessary to provide training workflows, including scenario activity, assessment attempts, answers, scores, review status, assignments, completion history, ratings, and organization-scoped or personal reporting.
We may also process technical, operational, and security information such as session records, audit events, application logs, browser or device information, IP addresses, timestamps, request information, and security events when needed to operate, maintain, troubleshoot, or protect the service.
First-party site analytics and attribution
SizeUpIQ uses limited first-party analytics to understand how the public website is being used, how visitors find SizeUpIQ, whether public features such as the demonstration scenario are being used, and whether those visits lead to actions such as account registration.
SizeUpIQ Site Analytics is operated directly by SizeUpIQ. It does not load Google Analytics, advertising pixels, or another third-party analytics service.
Analytics information is stored primarily as aggregate daily counters. Depending on the activity being measured, those aggregates may include the public page or route viewed, landing page, referring website domain, limited campaign attribution values such as `utmsource`, `utmmedium`, `utmcampaign`, and `utmcontent`, a coarse device category such as desktop, mobile, tablet, or other, and aggregate product events such as demonstration starts or completions, registrations, account verifications, training starts or completions, organization creation, organization invitations, or AI Private Beta access requests.
SizeUpIQ Site Analytics does not store IP addresses, full browser user-agent strings, full referring URLs, arbitrary URL query parameters, page contents, assessment answers, uploaded media, mouse movements, scroll activity, session recordings, or a persistent anonymous analytics identifier.
The normal SizeUpIQ application session may be used temporarily to avoid counting multiple public pageviews in the same browser session as separate visits and to preserve first-touch source or campaign attribution during that session. The Site Analytics database does not receive or store the application session identifier, and SizeUpIQ does not create a separate persistent analytics cookie or tracking identifier for this purpose.
External referring URLs are reduced to the referring domain before analytics information is stored. Browser information used to determine a coarse device category is processed transiently rather than stored as the full user-agent string.
SizeUpIQ may honor browser-provided privacy preference signals, including Global Privacy Control or Do Not Track, by excluding qualifying requests from Site Analytics. Automated bots and ordinary platform-administrator activity may also be excluded to improve the usefulness of aggregate measurements.
Aggregate Site Analytics records are retained for a limited configured period and are automatically pruned. Site Analytics is intended to measure overall service use, acquisition sources, feature adoption, and conversion trends rather than to build individual browsing profiles.
How we use information
We use information to create and administer accounts; authenticate users; maintain organization access controls; provide scenario authoring, training, assessments, assignments, reporting, Scenario Exchange, media, notifications, and support functionality; send required transactional messages; send optional notification emails when enabled by the account holder; maintain security and audit records; detect abuse; investigate technical problems; protect the service; comply with applicable legal obligations; enforce our Terms; and improve the reliability, accessibility, usability, and effectiveness of SizeUpIQ.
We may also use deidentified, aggregated, or statistical information that does not reasonably identify an individual to understand service performance, public-site usage, feature adoption, acquisition sources, and general usage trends.
Organizations and organization administrators
When your account belongs to an organization, information associated with that organization's training activity may be available to organization owners, administrators, instructors, reviewers, or other authorized users according to the organization's configured permissions and SizeUpIQ's access controls.
Organizations are responsible for deciding which users receive those permissions and for their own use of information obtained through organization features. Some records may belong to or be retained on behalf of an organization even if an individual account later leaves that organization.
Questions about an organization's internal use of training or personnel information may need to be directed to that organization.
Email and notifications
Required transactional messages, including account verification, password recovery, security notices, and organization invitations, may be sent when necessary to provide or secure the service.
In-app notifications are part of SizeUpIQ. Optional notification emails are sent only for eligible notification types when the account holder enables them and may be disabled through available preference controls.
AI-assisted features
When AI-assisted features are enabled and you choose to use them, SizeUpIQ may transmit instructions and content necessary to fulfill the request to the configured artificial-intelligence provider.
Do not submit information to AI-assisted functionality unless you or your organization are authorized to have that information processed in this manner. AI providers may process information according to their applicable service arrangements with SizeUpIQ.
Payments and commercial services
If paid services are enabled, payment and billing transactions may be handled by third-party payment processors. SizeUpIQ may receive transaction identifiers, customer identifiers, subscription or entitlement information, plan information, billing status, and limited payment metadata necessary to operate the service.
SizeUpIQ does not need to store full payment-card credentials when payment details are collected and processed directly by the applicable payment provider.
Service providers and integrations
SizeUpIQ may use service providers for hosting, infrastructure, storage, email delivery, identity, artificial intelligence, payment processing, diagnostics, security, and other functions necessary to provide the service.
Information may be provided to those services only to the extent reasonably necessary for the applicable function, subject to the provider's role and applicable agreements. A provider may process information in a jurisdiction different from yours.
SizeUpIQ's first-party Site Analytics does not require information to be sent to a third-party analytics provider.
Legal, safety, and security disclosures
SizeUpIQ may preserve, access, or disclose information when reasonably necessary to comply with applicable law, regulation, subpoena, court order, or lawful governmental request; investigate fraud, abuse, intellectual-property complaints, or security incidents; enforce our Terms; protect the rights or safety of users, organizations, SizeUpIQ, or others; or establish, exercise, or defend legal claims.
If ownership or operation of SizeUpIQ changes through a merger, acquisition, financing, reorganization, sale of assets, or similar transaction, information may be transferred as part of that transaction subject to applicable law and continued protection of the information.
Cookies and sessions
SizeUpIQ uses sessions, cookies, or similar technical mechanisms required for authentication, security, user preferences, CSRF protection, application operation, and limited first-party measurement as described in this Policy.
SizeUpIQ's first-party Site Analytics does not require a separate persistent analytics cookie or third-party analytics identifier.
If SizeUpIQ later introduces materially different advertising, cross-site tracking, behavioral profiling, third-party analytics, or other tracking technologies, this Policy will be updated as appropriate and those technologies will be configured consistently with applicable requirements.
Security
SizeUpIQ uses administrative, technical, and operational safeguards intended to protect information processed through the platform and to reduce the risk of unauthorized access, alteration, disclosure, or loss.
No internet service, software product, authentication system, network, cloud environment, storage system, or transmission method can guarantee absolute security. Security incidents can result from criminal activity, malicious third parties, compromised credentials or devices, software vulnerabilities, infrastructure failures, service-provider incidents, human error, or other causes.
Users and organization administrators also have responsibilities for protecting credentials and devices, assigning appropriate permissions, promptly removing unnecessary access, and limiting uploaded information to what is appropriate for the service.
Security incidents and data breaches
If SizeUpIQ becomes aware of a suspected security incident involving information under its control, SizeUpIQ may investigate the incident, take steps intended to contain or remediate it, preserve relevant records, involve service providers or authorities when appropriate, and take other actions reasonably necessary to protect the platform and affected users.
When applicable law requires notice to affected individuals, organizations, regulators, or others following a qualifying data breach, SizeUpIQ will provide or facilitate legally required notice in accordance with applicable requirements.
No provision of this Privacy Policy or the Terms of Use is intended to waive a privacy, security, breach-notification, or consumer-protection right or obligation that applicable law does not permit to be waived.
Retention and deletion
We retain information for as long as reasonably necessary to provide the service, maintain account and organization functionality, preserve security and audit history, meet contractual or legal obligations, resolve disputes, enforce agreements, and support legitimate organizational training records. Retention periods vary according to the nature and purpose of the information.
Aggregate Site Analytics information is retained for a limited configured period and is subject to automated retention and pruning controls.
A deletion request may not result in deletion of information that must lawfully be retained, is necessary for security or audit purposes, has been deidentified, belongs to an organization rather than solely to an individual account, or is otherwise subject to a lawful retention requirement.
Content shared through Scenario Exchange and subsequently copied by another authorized user or organization may exist independently of the original shared copy.
Your choices and privacy rights
You can update available profile information, account settings, and notification preferences through the service.
Depending on your location and whether a particular privacy law applies to SizeUpIQ and the relevant processing, you may have rights concerning access, confirmation, correction, deletion, portability, restriction, objection, opt-out choices, or information concerning certain disclosures or automated processing.
Requests may be sent to legal@mail.sizeupiq.com and may require reasonable identity verification. We will respond to applicable privacy requests as required by law.
International processing
SizeUpIQ users, infrastructure, and service providers may operate in different locations. Information may therefore be processed outside your state, province, or country where permitted by applicable law and applicable service arrangements.
Changes to this Privacy Policy
SizeUpIQ may update this Privacy Policy as the service, technology, legal requirements, or data practices change. The published version and effective date identify the current Policy.
When a revision materially affects account use or previously disclosed practices, SizeUpIQ may require users to review or acknowledge the new version before continuing normal account use.
Contact
Privacy questions, privacy-rights requests, security concerns, legal inquiries, or copyright and intellectual-property complaints may be sent to legal@mail.sizeupiq.com.
Operator: SizeUpIQ. Governing jurisdiction configured for these policies: State of Minnesota, United States of America.
Legal, privacy, and copyright contact: legal@mail.sizeupiq.com