IQExit respects your privacy and is committed to responsibledata handling. This Privacy Policy explains what information we collect, how weuse it, how long we retain it, and the choices available to users andinstitutional clients. It reflects IQExit’s published data retention andprivacy practices, including considerations relevant to institutional usersoperating under GLBA and similar privacy expectations.
1. Who We Are
IQExit provides a decision intelligence platform forbusiness ownership transitions. The platform generates Exit ReadinessIntelligence Reports for business owners and trusted advisors, includingbankers, wealth managers, CPAs, and other fiduciary professionals. IQExitoperates through an advisor-introduced model in which business owners accessthe platform through existing advisory relationships. Data sharing requiresexplicit owner permission.
2. Information We Collect
Depending on how you use the platform, IQExit may collectthe following categories of information:
Account Information
Name
Email address
Phone number for advisors
Organization name
City and state
Profile photo
Auth0 user ID
Business and Report Information
Company name
Annual revenue, EBITDA, or SDE
Business description
Industry classification
Location by state
Exit intent and timing
Website URL
Generated report content
Deal range estimates
Relationship and Sharing Information
Advisor-client relationship records
Report sharing records
Invitation records
Technical and Operational Information
Application logs
Error tracking data
API usage metrics
Access key usage
IP-address-based usage patterns and anomaly detection signals used for security monitoring
Billing Information
IQExit uses Stripe for payment processing. IQExit does notcollect, store, process, or transmit raw cardholder data. IQExit may receivelimited billing-related information such as Stripe customer ID, subscriptionstatus, and billing period details through Stripe webhooks.
3. How We Use Information
IQExit uses personal and business information to:
create and manage user accounts,
generate Exit Readiness Intelligence Reports,
perform AI-supported narrative analysis,
support billing and subscription management,
send email notifications,
operate, monitor, and secure the platform,
detect anomalous or abusive activity,
comply with legal, contractual, and institutional obligations.
4. AI Processing
IQExit uses Anthropic’s Claude API to generate narrativeanalysis within reports. Information sent for AI analysis may include businessdescription, revenue and profitability metrics, industry classification,geographic location by state, exit intent context, and publicly availablewebsite content when a URL is provided. IQExit does not send owner name, email,phone number, advisor identity, institutional affiliation, payment information,tax returns, financial statements, or uploaded documents to Anthropic.Anthropic API inputs are processed transiently and are not retained beyond therequest lifecycle, according to IQExit’s vendor documentation.
5. Legal Bases / Business Purposes
IQExit processes information for purposes including contractperformance, legitimate interest, consent where applicable, platform security,and customer relationship management. These purposes include report generation,AI analysis, account management, billing, email notifications, platformmonitoring, and anomaly detection.
6. Data Sharing
IQExit does not sell business data. Business data is notsold, licensed, or shared with third parties except as needed to operate theplatform and deliver requested services through approved service providers.External processors and infrastructure providers may include Render/AWS, Auth0,Anthropic, Stripe, AWS S3, Resend, Cloudflare, and Betterstack. IQExit statesthat material subprocessor changes affecting data processing will becommunicated to institutional clients with 30 days’ advance notice.
7. Where Data Is Stored
IQExit states that all data is stored and processed withinthe United States, specifically in AWS us-east-1 (Virginia), and that it doesnot transfer customer data outside the United States.
8. Security Measures
IQExit describes the following security controls:
TLS 1.2+ for data in transit,
AES-256 encryption at rest for PostgreSQL via AWS EBS,
server-side encryption for S3 objects,
Auth0-managed authentication,
configurable enterprise SSO and MFA,
role-based access control,
institution-level data isolation,
rate limiting,
security headers,
centralized logging and monitoring,
daily backups with point-in-time recovery,
no direct shell access to production servers.
9. Retention
IQExit’s documented retention periods include:
user account data: duration of account plus 90 days,
business report data: duration of account plus 1 year,
advisor-client relationship data: duration of relationship plus 1 year,
unused invitations: 90 days,
application logs: 30 days,
error tracking: 90 days,
API usage metrics: 1 year,
access key usage: 1 year.
10. Your Rights and Choices
Subject to applicable law and contractual requirements,users may:
access their data,
correct account information,
request deletion,
request data export,
download reports in PDF format,
request institutional exports in standard formats such as CSV or JSON. IQExit states that export requests are fulfilled within 30 days, deletion requests are processed within 30 days, and backup cleanup occurs within 90 days.
11. Institutional and GLBA Considerations
IQExit states that it may process Nonpublic PersonalInformation when business owners provide financial information throughinstitutional advisor relationships. IQExit’s stated safeguards includepermission-based sharing, institution-level data isolation, encryption, limitedaccess controls, and no secondary use of business data beyond generatingrequested reports. IQExit also notes that institutions should include IQExitwithin their own vendor management and GLBA compliance frameworks.
12. Enterprise Termination and Data Exit
Upon termination of an enterprise agreement, IQExit statesit will provide a complete data export within 30 days, deleteinstitution-specific data within 90 days after export confirmation, and providewritten confirmation of deletion.
13. Policy Updates
IQExit reviews and updates its policy as data practicesevolve. Material changes are communicated to institutional clients via emailwith 30 days’ advance notice.
14. ContactFor privacy questions or requests, contact:
support@iqexit.com
IQExit respects your privacy and is committed to responsible data handling.
This Privacy Policy explains what information we collect, how we use it, how long we retain it, and the choices available to users and institutional clients. It reflects IQExit's published data retention and privacy practices, including considerations relevant to institutional users operating under GLBA and similar privacy expectations.
IQExit provides a decision intelligence platform for business ownership transitions. The platform generates Exit Readiness Intelligence Reports for business owners and trusted advisors, including bankers, wealth managers, CPAs, and other fiduciary professionals. IQExit operates through an advisor-introduced model in which business owners access the platform through existing advisory relationships. Data sharing requires explicit owner permission.
Depending on how you use the platform, IQExit may collect the following categories of information:
Account Information
Business and Report Information
Relationship and Sharing Information
Technical and Operational Information
Billing Information
IQExit uses Stripe for payment processing and does not collect, store, or transmit raw cardholder data.
IQExit uses Anthropic's Claude API to generate narrative analysis within reports. Information sent for AI analysis may include business description, revenue metrics, industry classification, geographic location by state, and exit intent context. IQExit does not send owner name, email, phone, advisor identity, payment information, or uploaded documents to Anthropic. API inputs are processed transiently and not retained beyond the request lifecycle.
IQExit processes information for contract performance, legitimate interest, consent where applicable, platform security, and customer relationship management.
IQExit does not sell business data. Business data is not sold, licensed, or shared with third parties except as needed to operate the platform. External processors may include Render/AWS, Auth0, Anthropic, Stripe, AWS S3, Resend, Cloudflare, and Betterstack. Material subprocessor changes will be communicated to institutional clients with 30 days' advance notice.
All data is stored and processed within the United States, in AWS us-east-1 (Virginia). IQExit does not transfer customer data outside the United States.
Subject to applicable law, users may access their data, correct account information, request deletion, request data export in CSV or JSON, and download reports in PDF format. Export and deletion requests are fulfilled within 30 days; backup cleanup within 90 days.
IQExit may process Nonpublic Personal Information when business owners provide financial information through institutional advisor relationships. Safeguards include permission-based sharing, institution-level data isolation, encryption, and no secondary use of business data. Institutions should include IQExit within their own vendor management and GLBA compliance frameworks.
Upon termination, IQExit will provide a complete data export within 30 days, delete institution-specific data within 90 days after export confirmation, and provide written confirmation of deletion.
Material changes are communicated to institutional clients via email with 30 days' advance notice.
For privacy questions or requests: support@iqexit.com