Privacy Policy
Last updated: August 12, 2026
This Privacy Policy explains how BonsaiTechnologySystems, Inc., a Delaware corporation having its office at 80 Revere Road, Monmouth Junction, NJ 08852 ("Company," "Bonsai," "we," or "us") collects, uses, and shares personal data in connection with our platform and services (the "Services"). It applies to visitors to our website and to individuals at our business customers who use the Services. Capitalized terms not defined here have the meaning given in our Terms of Service.
Bonsai is a business-to-business provider. We are not designed for, and ask that you not submit through the Services, sensitive or specially protected data (for example, health, payment card, or government ID data), as described in our Terms.
1. Data We Collect
We collect the following categories of personal data:
- Account and registration data — name, business name, address, phone number, email address, and related business details you provide when you register or manage an account.
- Customer Data — content and materials you or your users submit to the platform in order to receive the Services, which may incidentally include contact details of your personnel.
- Usage data — technical logs, device and browser information, and data about how you interact with the platform and Services.
- Cookies and similar technologies — data collected through cookies and comparable tools on our website (see Section 6).
2. How We Use Data
We use personal data to:
- Provide, operate, maintain, and secure the platform and Services;
- Set up and administer accounts and communicate with you, including operational and service notices;
- Improve and support the platform and Services, and for analytics, benchmarking, and reporting (published only in de-identified, aggregated form);
- Comply with law and enforce our agreements.
3. How We Share Data
We do not sell personal data. We share it only as needed to run the Services:
- Service providers and sub-processors who help us deliver the Services — including cloud infrastructure and AI providers such — under confidentiality and data-protection obligations. Our current sub-processors are identified in our Trust Center.
- Third-party platforms you choose to connect — handled under your agreement with that provider, not this Policy;
- Legal and safety disclosures where required by law, subpoena, or court order, or to protect rights, safety, and the integrity of the Services;
- Business transfers in connection with a merger, acquisition, or sale of assets.
4. International Transfers and Data Location
We process personal data on United States–based infrastructure, and may store or process it in other countries as approved or directed by our customers. Where we transfer personal data out of the European Economic Area, the UK, or Switzerland, we apply appropriate safeguards required by law, such as the European Commission’s Standard Contractual Clauses. Business customers processing EU, UK, or Swiss personal data through the Services may enter into our Data Processing Addendum, which governs that processing.
5. Data Retention
We retain personal data for as long as needed to provide the Services and for legitimate business or legal purposes. On expiration or termination, Customer Data is handled as described in our Terms; residual copies may remain in routine backups for a limited period and stay subject to this Policy.
6. Cookies
Our website uses cookies and similar technologies to operate the site, remember preferences, and understand usage. You can control cookies through your browser settings; disabling some cookies may affect site functionality.
7. Security
We use reasonable technical and organizational measures designed to protect personal data. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
8. Your Rights (EU/EEA and UK)
If you are in the EEA or UK, you have rights under the GDPR to access, correct, delete, restrict, or object to the processing of your personal data, to data portability, and to withdraw consent where processing is based on consent. Our legal bases for processing are: performance of a contract, our legitimate interests in operating and improving the Services, compliance with legal obligations, and, where applicable, your consent.
For personal data our customers submit through the Services, the customer is the controller and Bonsai acts as a processor; individuals should direct such requests to the relevant customer, and we assist our customers in responding as set out in our Data Processing Addendum. For data we control directly (for example, account and website data), you may contact us using the details below. You also have the right to lodge a complaint with your local supervisory authority.
9. Children
The Services are intended for businesses and are not directed to children. We do not knowingly collect personal data from children.
10. Changes to This Policy
We may update this Policy from time to time to reflect new features or changing practices, with notice to customers as required by contract. Changes will not materially decrease our overall obligations during the term of your agreement. The "Last updated" date above reflects the current version.
11. Contact Us
If you have questions about this Policy or our data practices, contact us at:
Bonsai30 Revere Road, Monmouth Junction, New Jersey 08852
security@hibonsai.com
