Privacy Policy
Last Updated: February 8, 2026
This Privacy Policy describes how Holborn LLC ("Holborn", "we", "us", "BuildSherpa Research") collects, uses, stores, and shares your information when you use the BuildSherpa Research platform at research.buildsherpa.ai (the "Service"). This policy should be read in conjunction with our Terms of Service.
1. Information We Collect
1.1 Information You Provide
We collect information you provide when you:
- Create an account: Email address, name, password (hashed)
- Set up your profile: Company name, role, firm type
- Upload brand assets: Company logo, brand colors
- Configure analyses: Research questions, target companies, sector selections, clarifying answers
- Make payments: Payment information processed by Stripe (we do not store credit card details)
- Contact us: Email communications and support requests
1.2 Information Collected Automatically
When you use the Service, we automatically collect:
- Usage data: Reports generated, features used, export history, session duration
- Device information: IP address, browser type, operating system
- Cookies: Session cookies for authentication and preferences (see Section 4)
2. How We Use Your Information
2.1 Service Delivery
We use your information to:
- Generate market analysis reports based on your research parameters
- Apply your branding (logo, colors) to exported deliverables
- Process payments and manage your account
- Provide customer support
2.2 Platform Improvement
We use your information to:
- Monitor and improve Service performance and reliability
- Develop new features based on usage patterns
- Train and improve AI models using anonymized data
- Generate aggregate industry benchmarks
Data used for improvement purposes is anonymized and aggregated so it cannot be traced to you or your organization.
2.3 Communication
We use your information to send:
- Transactional emails (account verification, receipts, report completion)
- Service notifications (maintenance, feature updates)
- Marketing communications (with your consent; opt-out available)
2.4 Legal and Security
We use your information to detect fraud, comply with legal obligations, enforce our terms, and protect the security of the Service.
3. Anonymized Data
As described in our Terms of Service, we may aggregate and anonymize usage data for AI training, platform improvement, and industry research. Once anonymized, this data becomes our property and is not subject to deletion requests, as it cannot identify you.
4. Cookies
We use cookies for:
- Essential cookies: Authentication, session management, security
- Analytics cookies: Understanding usage patterns to improve the Service
- Preference cookies: Remembering your settings
You can control cookies through your browser settings. Disabling essential cookies may prevent the Service from functioning properly.
5. Information Sharing
5.1 Service Providers
We share data with third-party providers who process data on our behalf:
- Hetzner (Germany): Cloud hosting and storage
- Google Cloud (USA): AI model APIs for analysis generation
- Stripe (USA): Payment processing
- Email provider (USA/EU): Transactional email delivery
These providers operate under data processing agreements with appropriate safeguards for international transfers.
5.2 Legal Requirements
We may disclose information when required by law, subpoena, court order, or government request.
5.3 Business Transfers
In a merger, acquisition, or sale of assets, your information may transfer to the acquiring entity. We will notify you before your data becomes subject to a different privacy policy.
5.4 Confidentiality of Research Activities
We treat your research queries, target companies, analysis parameters, and report content as confidential business information. We will not disclose your specific research activities to third parties, competitors, or other users of the Platform.
6. Legal Bases for Processing (GDPR)
For users in the EEA, UK, or Switzerland, we process data under:
- Contract fulfillment: Providing the Service and processing payments
- Legitimate interests: Analytics, improvement, fraud prevention, anonymized data usage
- Legal obligation: Compliance with applicable laws
- Consent: Marketing communications and non-essential cookies
7. Data Security
We implement reasonable technical and organizational measures to protect your information:
- Encrypted data transmission (HTTPS/TLS)
- Password hashing using industry-standard algorithms
- Access controls and role-based permissions
- Regular security monitoring
No system is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
8. Data Retention
- Account data: Retained while your account is active and up to 90 days after deletion
- Reports and analyses: Retained while your account is active
- Usage data: Up to 24 months for analytics purposes
- Anonymized data: Retained indefinitely (not personal data)
- Financial records: 7 years per tax and accounting regulations
9. Your Rights
9.1 General Rights
You may:
- Access: Request a copy of your personal data
- Correct: Request correction of inaccurate data
- Delete: Request deletion (subject to legal retention requirements)
- Object: Object to processing for certain purposes
- Portability: Request your data in a machine-readable format
- Withdraw consent: Withdraw consent for marketing or non-essential cookies
9.2 GDPR Rights
EEA/UK/Swiss users may lodge complaints with their local data protection authority.
9.3 CCPA/CPRA Rights
California residents have the right to know, delete, correct, and opt-out of data sharing. We do not sell personal information in the traditional sense, though anonymized data usage may qualify as "sharing" under CPRA.
9.4 Exercising Rights
Contact support@buildsherpa.ai with the subject "Privacy Rights Request". We respond within 30 days. Identity verification may be required.
10. International Transfers
Data is stored and processed in Germany (Hetzner) and the USA (Google Cloud, Stripe). International transfers from the EEA/UK are protected by Standard Contractual Clauses and Data Processing Agreements.
11. Children's Privacy
The Service is not directed to individuals under 16. We do not knowingly collect data from children.
12. Changes to This Policy
We may update this policy to reflect changes in our practices or legal requirements. Material changes will be communicated by email. Continued use after changes take effect constitutes acceptance.
13. Contact
Email: support@buildsherpa.ai
Subject: Privacy Inquiry
Address: Holborn LLC, 30 N Gould St Ste R, Sheridan, WY 82801, USA