CORDYN SECURITY MANAGEMENT
PRIVACY POLICY
Contents
Provided by Modul Development LLC
Business-to-Business SaaS Privacy Policy
This Privacy Policy explains how Modul Development LLC ("Modul," "we," "us," or "our") collects, uses, discloses, stores, and protects information in connection with Cordyn Security Management, including Cordyn websites, tenant workspaces, customer portals, APIs, integrations, and related services (collectively, the "Service").
Cordyn is a business-to-business security-management platform used by security companies and other organizations, their administrators and personnel, and authorized client users. This Policy covers information Modul collects for its own business purposes and information Modul processes on behalf of Cordyn Customers.
When a Cordyn Customer determines the purposes and means of processing information placed in its tenant, that Customer generally acts as the business, controller, employer, or other responsible organization, and Modul generally acts as a service provider, contractor, processor, or similar provider on the Customer's instructions. The precise legal role depends on applicable law and the specific processing activity.
If your employer, security company, client, or another organization entered your information into Cordyn, questions about that Customer-controlled information should generally be directed to that organization first.
1. INFORMATION WE COLLECT
The information we collect depends on how you interact with Cordyn, what features are actually available and enabled, and how the applicable Customer configures the Service.
1.1 Account and Identity Information
We may collect:
- Name;
- Business email address;
- Organization or employer;
- Job title or role;
- Employee or personnel identifier where provided;
- Assigned role and access scope;
- Account and invitation status;
- Authentication and session information;
- MFA enrollment status and encrypted factor information;
- Hashed recovery-code information;
- Password-reset and account-recovery status; and
- Other information necessary to establish, administer, or secure an account.
Passwords are stored using password-hashing mechanisms rather than as readable plaintext passwords. Raw invitation tokens, password-reset tokens, and recovery codes are designed to be short-lived or one-time credentials and are not intended to be stored in readable form after issuance.
1.2 Approved Email and Invitation Information
Cordyn uses invite-only account activation for normal Customer access. We may process the exact approved email address, approved domain, invitation status, tenant/workspace, intended role, expiration, acceptance status, and related security information needed to determine whether an invitation is valid and authorized.
1.3 Multi-Factor Authentication Information
Cordyn may require TOTP-based or other supported MFA. We may process MFA enrollment status, encrypted authentication-factor data, verification timestamps, failed verification events, recovery-code status, session information, and security events. Modul does not need access to the contents of a user's separate authenticator application.
2. CUSTOMER AND ORGANIZATION INFORMATION
When an organization becomes a Cordyn Customer, we may process company name, business contact information, authorized domains, owner and administrator contacts, billing contacts, subscription and entitlement information, tenant configuration, workspace slug or subdomain, storage allocation and usage, branding settings, onboarding status, and related account-administration information.
3. WORKFORCE AND PERSONNEL INFORMATION
Where Customer enables and uses workforce functionality, Customer may provide or create information about employees, guards, supervisors, contractors, or other personnel, such as name, contact details, employee number, position, supervisor, assigned sites, work status, availability, licenses, credentials, certifications, training records, qualifications, equipment assignments, emergency contacts, and related documents.
This information is generally provided by or on behalf of Customer and processed by Modul on Customer's instructions. Modul does not determine Customer's employment policies or legal basis for collecting workforce information.
4. CLIENT, SITE, CONTRACT, AND COMMERCIAL INFORMATION
Customers may store or generate client names, business contacts, site addresses, site contacts, access instructions, post orders, emergency contacts, property information, service requirements, opportunities, assessments, proposals, contracts, obligations, launch information, service-change information, renewal information, and other Customer business records. Access is controlled according to the Customer's authorized users and configuration.
4.1 Electronic Signature and Contract Execution Information (Cordyn Sign)
Cordyn may provide electronic-signature and electronic-contracting functionality under the name Cordyn Sign. When a Customer uses Cordyn Sign to send a contract, amendment, change order, renewal, acknowledgment, or similar business record for electronic signature, Cordyn processes information about the transaction and the people who sign or are asked to sign. Depending on the workflow, this information may include:
- Signer name, business email address, title, organization, and signing role;
- Typed or drawn signatures and initials, and values entered in signature-request fields;
- Signing, consent, verification, and completion timestamps;
- The electronic-signature disclosure version accepted and the signer-authority and intent-to-sign attestations confirmed;
- The authentication method used for the signing session and one-time-code verification events;
- IP address and browser or user-agent information recorded at signing-session events;
- Document identifiers, contract identifiers, document versions, and cryptographic document hashes;
- Signing-event history, including delivery, viewing, verification, signature, decline, reminder, cancellation, expiration, and completion events;
- The document presented for signature, the executed agreement with applied signatures, execution summary pages, and Certificates of Completion; and
- Related signing communications and their delivery status.
4.2 Signers Who Are Not Cordyn Users
Cordyn Sign may process information about people who do not have Cordyn accounts, such as a Customer's clients, authorized representatives, procurement contacts, contract signers, witnesses where supported, and other counterparties. A signer receives a secure signing link and does not need to create a Cordyn account to review, consent to, and sign a document. The Customer that sends the request determines who is asked to sign and what the document contains.
4.3 Drawn Signatures Are Not Biometric Identification
Where a signer draws a signature or initials, Cordyn processes the drawn image as an electronic-signature artifact that is applied to the executed document and retained as part of the transaction record. Cordyn does not analyze drawn signatures to identify or authenticate individuals and does not use them for biometric identification, biometric authentication, or behavioral biometrics. If a future feature were to do so, separate disclosures and any required consent would apply first.
4.4 Signing Communications
Using contact information supplied by the Customer, Cordyn may send signature invitations, verification codes, reminders, completion notices, decline notices, and other transactional signing communications on the Customer's behalf. These messages are transactional, not marketing. Customers are responsible for supplying accurate and appropriate recipient contact details.
4.5 Verification Codes and Signing-Session Authentication
Cordyn may authenticate access to a signing session through a unique signing link sent to the invited email address and, where the Customer requires it, a one-time verification code. Signing links and verification codes are security and authentication data: Cordyn stores them only in hashed form bound to the specific signer and request, they expire, verification attempts are limited, and a code cannot be reused once verified. Cordyn does not treat email possession, a verification code, an IP address, or a typed name as proof of a person's legal identity.
4.6 Cryptographic Document Identifiers
Cordyn computes cryptographic hashes of the document presented for signature and of the executed record. A hash is a fixed-length fingerprint used to verify integrity and to associate signatures and evidence with the exact document version; it does not contain the readable contents of the document.
4.7 Consent and Attestation Records
Cordyn retains records showing which electronic-signature disclosure was shown to a signer, which version the signer accepted and when, and the signer's authority and intent-to-sign confirmations. These records form part of the electronic transaction record.
4.8 Executed Records and Certificates of Completion
After a signing request is completed, Cordyn generates and stores the executed agreement with the applied signatures or initials and an execution summary, together with a Certificate of Completion documenting the signing process and evidence. These records are stored in the Customer's Cordyn storage allocation under the Customer's subscription and the retention terms of this Policy; they are not retained indefinitely by default, and Cordyn is not a permanent legal archive unless separately agreed in writing.
5. SECURITY REPORTS AND OPERATIONAL RECORDS
Where corresponding features are made available or integrated, Cordyn may process incident reports, activity reports, supervisor records, patrol information, observations, statements, photographs, documents, involved-person or vehicle information, response information, service-delivery information, and other operational records created by Customer personnel or received through authorized integrations.
The content of Customer operational records is determined primarily by Customer and its users. Customer is responsible for limiting collection and access to information reasonably necessary and lawful for its operations.
6. LOCATION INFORMATION
Where location functionality is actually implemented, enabled, or received from an authorized integration, Cordyn may process site locations, report locations, checkpoint or patrol locations, device or vehicle location, GPS coordinates, or approximate location information. Cordyn does not require continuous location monitoring unless a specific feature is made available and enabled.
Customer is responsible for providing required notices and obtaining legally required consent before using location-tracking functionality, including where precise geolocation is treated as sensitive personal data.
7. DEVICE, LOG, AND TECHNICAL INFORMATION
When you access Cordyn, we may automatically process technical information such as IP address, browser type, operating system, device type, application version, login and authentication timestamps, session identifiers, requested resources, user-agent information, error data, API activity, security events, and approximate region inferred from network information where used. We use this information to operate, troubleshoot, secure, and improve the Service.
For Cordyn Sign signing sessions, IP address and user-agent information are also recorded when a signer opens a signing link, accepts a disclosure, verifies a code, signs, or declines, as supporting security and transaction evidence. Such information supports security, authentication context, fraud prevention, audit history, transaction evidence, and dispute resolution; it does not by itself establish a person's identity.
8. AUDIT AND SECURITY LOGS
Cordyn may record account creation, invitations, login attempts, MFA events, password and security changes, role or permission changes, administrative actions, document activity, integration activity, exports, configuration changes, API events, and other security-relevant activity. Some audit records may be visible to authorized Customer administrators; infrastructure and security logs may be available only to Modul personnel with an operational need.
9. FILES, ATTACHMENTS, AND STORAGE
Cordyn may allow Customers to upload supported documents, photographs, reports, post orders, training records, personnel documents, and other attachments. Files are stored within Cordyn-controlled or approved infrastructure and associated with the applicable tenant. Customer subscriptions may include a storage quota, and Cordyn may maintain usage and allocation information.
10. SUPPORT INFORMATION AND SUPPORT ACCESS
When you or a Customer contacts Modul for support, we may process name, email address, organization, support request, correspondence, screenshots, diagnostic information, and other information voluntarily provided.
Modul platform administrators do not receive routine access to Customer business records solely by virtue of platform-admin status. If Customer Data access is reasonably necessary for support, security investigation, legal compliance, or an authorized service, access is limited to authorized personnel and the scope reasonably necessary for the purpose and may be subject to access controls and audit logging.
The Modul Control Plane used to operate Cordyn does not provide routine access to Customer contracts, signature requests, signatures, or signing evidence, and platform administrators cannot sign, alter, or replace Customer signing records. Any support access to such records is authorized, limited to what is reasonably necessary, access controlled, and audited.
11. BILLING AND TRANSACTION INFORMATION
If Customer purchases Cordyn directly from Modul, we may process subscription level, billing contacts and addresses, invoice history, payment status, transaction identifiers, and related accounting information. Complete payment-card numbers should be handled by an approved payment provider rather than stored directly in Cordyn unless Modul expressly implements compliant payment infrastructure.
12. INFORMATION FROM THIRD-PARTY INTEGRATIONS
Cordyn may receive or transmit information through Customer-authorized or Modul-operated integrations, such as CAD or MDT systems, identity providers, email services, HR or payroll platforms, scheduling systems, mapping services, payment providers, messaging services, APIs, or other business systems. The information processed depends on the integration and its authorized scope.
13. HOW WE USE INFORMATION
We may use information to:
- Provide, operate, maintain, and secure Cordyn;
- Create tenants, workspaces, invitations, and accounts;
- Authenticate users and enforce MFA, roles, permissions, and tenant boundaries;
- Store and process Customer Data on Customer's instructions;
- Operate Customer-authorized workflows, portals, APIs, and integrations;
- Provide notifications and transactional email;
- Maintain audit and security logs;
- Respond to support requests and investigate technical problems;
- Detect, prevent, and investigate fraud, abuse, and security incidents;
- Maintain backups and recovery capabilities;
- Administer subscriptions, storage, and platform operations;
- Improve reliability, usability, and security;
- Communicate with Customers and users;
- Enforce agreements and protect legal rights; and
- Comply with applicable law.
For Cordyn Sign transactions, information described in Section 4.1 may also be processed to:
- Prepare electronic-signature transactions from Customer documents and Customer records;
- Deliver signing requests, reminders, and completion notices to the recipients the Customer designates;
- Authenticate access to signing sessions and verify transaction access;
- Capture electronic consent to conduct the transaction electronically;
- Capture signer-authority and intent-to-sign confirmations;
- Apply signatures and initials to the document presented for signature;
- Generate executed documents and Certificates of Completion;
- Preserve transaction history and protect document integrity;
- Detect and prevent fraud, misuse, and unauthorized access;
- Maintain audit evidence and support dispute resolution;
- Provide Customer support;
- Satisfy legal, regulatory, contractual, and security obligations; and
- Retain and reproduce executed records for the periods described in this Policy.
14. OUR ROLE FOR CUSTOMER DATA
For Customer Data, Customer generally determines what information to collect, why it is processed, who may access it, how long it should be retained, and which authorized integrations may receive it. Modul processes that information primarily to provide Cordyn according to Customer's documented instructions, applicable agreements, and law.
Where applicable, Modul may act as a service provider, contractor, processor, or similar provider for Customer Data. Modul separately acts as a business, controller, or equivalent entity for information processed for Modul's own purposes, such as platform account administration, security, fraud prevention, billing, direct Customer communications, legal compliance, and operation of the Cordyn business.
For contracts and signature transactions processed through Cordyn Sign, the Customer generally determines the business purpose for sending a document, selects the signers, and decides the contents of the agreement. Modul provides Cordyn Sign as the Customer's service provider or processor where applicable and does not become a party to a Customer's contract merely because the contract was prepared, transmitted, signed, or stored through Cordyn. Modul may separately process limited account, security, delivery, and operational information about signing transactions for its own purposes where legally appropriate, such as security, fraud and abuse prevention, service administration, and legal compliance.
15. DATA MINIMIZATION AND PURPOSE LIMITATION
Modul seeks to process personal information that is adequate, relevant, and reasonably necessary for the disclosed purposes. Customers are responsible for configuring their own forms, records, permissions, and collection practices so that Customer Data is likewise limited to information reasonably necessary and lawful for their business purposes.
16. WE DO NOT SELL CUSTOMER DATA
Modul does not sell Customer Data or personal information contained within Cordyn Customer tenants. Modul does not sell security reports, personnel records, client information, operational records, or Customer confidential information to third parties.
Modul does not share Cordyn Customer operational information for cross-context behavioral advertising and does not use Customer Data to build third-party behavioral advertising profiles.
Cordyn Sign signature transactions, executed agreements, Certificates of Completion, and signing evidence are Customer Data for these purposes: Modul does not sell them and does not use them for behavioral advertising.
17. ARTIFICIAL INTELLIGENCE
Cordyn may offer AI-assisted functionality in the future or for specifically identified features. Unless separately disclosed and agreed, Modul does not use Customer confidential data or Customer operational data to train publicly available or general-purpose AI models. If an AI-enabled feature processes Customer Data, additional terms, disclosures, configuration, or Customer instructions may apply.
Contracts, signature data, Certificates of Completion, signing evidence, and other Customer confidential or operational records processed through Cordyn Sign are not used to train publicly available or general-purpose AI models.
18. AUTOMATED DECISION-MAKING
Cordyn is intended to assist human users. Unless a specific feature is separately disclosed and legally configured, Cordyn is not intended to make legally significant employment, disciplinary, criminal, insurance, credit, housing, healthcare, education, or similar decisions about individuals without meaningful human involvement. Customer remains responsible for decisions made using Cordyn information.
19. HOW WE DISCLOSE INFORMATION
We may disclose information only as reasonably necessary for the purposes described in this Policy, including to:
- Authorized Customer administrators and users according to Customer permissions;
- Service providers and subprocessors that assist with hosting, databases, storage, backups, authentication, email delivery, monitoring, security, payment processing, customer support, or other necessary technology;
- Customer-authorized third-party integrations;
- Professional advisers subject to confidentiality obligations;
- Governmental or legal authorities when disclosure is required or permitted by law; and
- A successor or transaction counterparty in connection with a merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or transfer of the Cordyn business, subject to applicable obligations.
For transactional email, including Cordyn Sign signature invitations, verification codes, reminders, and completion notices, Modul currently uses the Google Workspace email relay or another configured email provider. Signing communications are sent from a Modul-controlled address that displays the sending Customer's name. Provider use may change as Cordyn evolves.
20. LEGAL REQUESTS
We evaluate legal requests for appropriate authority. Where legally permitted and appropriate, Modul may require valid legal process, limit disclosure to responsive information, challenge requests that appear unlawful or overly broad, and notify the affected Customer. Nothing prevents Modul from responding to an emergency involving imminent risk of death or serious physical injury where disclosure is lawfully permitted.
21. COOKIES AND SIMILAR TECHNOLOGIES
Cordyn may use cookies or similar technologies necessary for authentication, session management, CSRF protection, security, preferences, and application functionality. Non-essential analytics or similar technologies, if introduced, will be handled in accordance with applicable notice or consent requirements. Disabling essential cookies may prevent the Service from functioning.
22. ANALYTICS AND SERVICE IMPROVEMENT
Modul may analyze technical, performance, security, and usage information to operate and improve Cordyn. Where practical, analytics are designed to minimize collection of Customer confidential information. Customer operational content is not intentionally provided to advertising networks or analytics providers for third-party advertising purposes.
23. DATA RETENTION
We retain information for as long as reasonably necessary for the purposes described in this Policy, including to provide the Service, maintain Customer accounts, preserve audit integrity, protect security, fulfill contractual obligations, maintain financial records, comply with law, resolve disputes, and enforce agreements.
Retention varies by data type and context. Invitation and password-reset credentials are short-lived; session and authentication records expire or are revoked according to security rules; Customer business data is generally retained according to Customer instructions, subscription status, contractual requirements, and applicable law; and backup copies may remain until expiration or overwrite through normal backup cycles. A Customer agreement or Data Processing Addendum may establish more specific retention terms.
Cordyn Sign records are retained as part of the Customer's contract records. Completed signing records, executed agreements, Certificates of Completion, signing evidence, and related audit history are retained according to the Customer's subscription, the Customer's retention configuration and instructions, Cordyn's retention practices, applicable agreements, and legal and security obligations. Signing evidence associated with a completed, cancelled, expired, or declined request is preserved rather than deleted while the underlying record exists, and some information may remain in backups, security records, audit records, legal holds, and transaction evidence for applicable periods. Cordyn does not promise permanent archival, and Customers remain responsible for exporting and independently retaining executed agreements that must be preserved for a statutory, contractual, tax, insurance, employment, litigation, or regulatory period.
24. CUSTOMER DATA DELETION
Customer may request deletion or return of Customer Data subject to applicable agreements, legal obligations, active disputes, security investigations, audit-integrity requirements, and technical limitations reasonably necessary to operate the Service. Deletion from active systems may not result in immediate deletion from backups. Backup copies are removed through the applicable expiration or overwrite cycle unless law or a signed agreement requires a different process.
Deletion requests do not extend to executed agreements, Certificates of Completion, signing evidence, and audit records that Modul or the Customer is legally required or permitted to retain, including where such records are needed to establish the validity of an electronic signature or to resolve a dispute.
25. ACCOUNT DEACTIVATION
Deactivating a user does not necessarily delete reports, audit events, contracts, or other organizational records created by that user. Modul and Customer may retain account identifiers or history where reasonably necessary for audit integrity, security, compliance, legal obligations, or Customer recordkeeping.
26. SECURITY
Modul uses administrative, technical, and organizational safeguards designed to protect information processed through Cordyn. Depending on the deployed feature and context, safeguards may include TLS-protected communications, password hashing, MFA, role-based access controls, tenant separation, host-bound sessions, access and audit logging, backup processes, secure development practices, request and rate protections, and administrative access restrictions.
For Cordyn Sign, safeguards include tenant separation, authenticated tenant access, opaque signing links stored only as hashes, hashed and expiring verification codes with attempt limits, cryptographic hashing and freezing of the document presented for signature and of the executed record, step-up multi-factor authentication for sensitive tenant operations, role-based permissions with separately controlled access to detailed signing evidence, Customer-scoped storage, audit events, durable email delivery jobs, and rate limiting.
No method of transmission or storage is completely secure, and Modul cannot guarantee absolute security. Customers remain responsible for their own endpoints, networks, users, credentials, connected systems, and lawful configuration of the Service.
27. TENANT SEPARATION
Cordyn is designed as a multi-tenant SaaS platform. Logical authorization controls are intended to prevent one Customer from accessing another Customer's information. Users may access only tenants and resources for which they are authorized. Attempts to circumvent tenant isolation or authorization controls are prohibited.
28. SECURITY INCIDENTS
If Modul becomes aware of unauthorized access to Customer Data requiring notification under applicable law or a signed agreement, Modul will take reasonable steps to investigate, contain, mitigate, preserve relevant evidence, notify affected Customers when required, and satisfy applicable notification obligations. Customers should promptly notify Modul if they suspect compromise of Cordyn accounts, administrator credentials, API keys, or connected systems.
29. DATA STORAGE AND HOSTING
Cordyn data may be hosted on infrastructure operated or controlled by Modul and approved service providers. Production data, document storage, backups, logs, and security information may be stored in different systems or locations as Cordyn infrastructure evolves. Customers with specific data-residency or regulated-hosting requirements should confirm those requirements with Modul in writing before placing regulated information in the Service.
30. INTERNATIONAL DATA TRANSFERS
Cordyn or its service providers may process information in jurisdictions different from the location of Customer or user. Where applicable law requires a transfer mechanism or contractual safeguard, Modul will use an appropriate mechanism consistent with its role and the applicable agreement.
31. PRIVACY RIGHTS
Depending on applicable law and Modul's role for the information, individuals may have rights to request access, correction, deletion, portability, restriction, objection, withdrawal of consent where consent is the legal basis, or appeal of certain privacy decisions. Rights are not absolute and may be subject to verification, legal exceptions, Customer instructions, and other limitations permitted by law.
Requests concerning Cordyn Sign records are subject to the same limitations: executed agreements, Certificates of Completion, and signing evidence that Modul or a Customer is legally required or permitted to retain are not deleted in response to a request, and Modul may verify the identity and authority of a requester before acting.
32. HOW TO SUBMIT A PRIVACY REQUEST
For information Modul controls directly, a privacy request may be submitted to privacy@getmodul.app with the subject "Privacy Request." Please describe the request and provide enough information for us to identify the relevant account or interaction. Do not send passwords, MFA secrets, or recovery codes.
We may verify identity or authority before fulfilling a request. We will respond within the period required by applicable law. Where a law provides a 45-day response period, we will respond within that period unless a lawful extension applies and notice of the extension is provided.
33. REQUESTS RELATING TO CUSTOMER DATA
If personal information was placed in Cordyn by your employer, security company, client, contractor, or another Cordyn Customer, that Customer generally controls the information and should receive the request first. If Modul receives a request concerning Customer-controlled data, we may refer the requester to Customer or assist Customer in responding as appropriate and legally required.
Signers who received a signing request from a Cordyn Customer should direct questions about the agreement, the request, or their information to that Customer, which controls the transaction; Modul will assist as appropriate and legally required.
34. PRIVACY APPEALS
Where applicable law provides a right to appeal a denied privacy request, you may appeal by emailing privacy@getmodul.app with the subject "Privacy Appeal" and identifying the prior request or decision. We will review the appeal and respond within the period required by applicable law. If applicable law requires us to provide information about submitting a complaint to a regulator after an appeal is denied, we will include that information in our response.
35. U.S. STATE PRIVACY RIGHTS
Residents of certain U.S. states may have additional rights concerning personal information where the applicable statute applies to Modul or the relevant processing. These may include rights to know or access, correct, delete, obtain a portable copy, opt out of certain sales, targeted advertising, or qualifying profiling, limit certain uses of sensitive information, and appeal certain decisions. Modul does not sell Customer Data and does not use Cordyn Customer operational information for targeted advertising.
36. CALIFORNIA PRIVACY
If the California Consumer Privacy Act, as amended ("CCPA"), applies to Modul or a Cordyn Customer in a particular context, California residents may have rights provided by that law, including rights concerning access, correction, deletion, and information about collection, use, disclosure, sale, or sharing of personal information, subject to applicable exceptions.
Depending on the processing, Modul may act as a business or as a service provider or contractor processing information on behalf of a Customer. For Customer Data processed on behalf of a Customer, privacy requests generally should be directed to that Customer first. Modul does not sell personal information contained in Cordyn Customer tenants and does not share Cordyn Customer operational information for cross-context behavioral advertising.
37. TEXAS PRIVACY
Where the Texas Data Privacy and Security Act ("TDPSA") applies, Texas consumers may have rights to confirm processing and access data, correct inaccuracies, delete qualifying data, obtain certain portable data, and opt out of qualifying targeted advertising, sale, or profiling. Qualifying consumers may also appeal certain decisions.
Where Modul acts as a processor for Customer Data, Customer generally serves as the controller responsible for responding to consumer requests, and Modul will provide reasonable assistance consistent with applicable law and the parties' data-processing agreement. Where Modul acts as a controller, requests and appeals may be submitted using the methods described above.
38. SENSITIVE PERSONAL DATA
Certain laws classify categories such as precise geolocation, biometric identifiers, racial or ethnic origin, religious beliefs, health information, sexual orientation, citizenship or immigration status, and information about known children as sensitive personal data. Cordyn does not require Customers to collect such information unless a particular supported workflow calls for it.
Customer is responsible for determining whether Customer-directed processing of sensitive information is lawful and for obtaining consent or providing notices when required. Customers should not use Cordyn for biometric recognition, HIPAA-regulated protected health information, or other specially regulated data unless Modul has expressly confirmed in writing that the applicable feature and contractual safeguards support that use.
39. EMPLOYMENT AND WORKFORCE INFORMATION
Customer is responsible for determining whether its collection and processing of employee, guard, supervisor, contractor, applicant, or other workforce information complies with applicable employment, privacy, monitoring, notice, consent, labor, discrimination, and contractual requirements. Modul provides the platform and does not determine Customer's employment policies or decisions.
40. BIOMETRIC INFORMATION
Unless Cordyn expressly provides and documents a biometric feature, Customers should not use Cordyn to collect biometric identifiers for biometric-recognition purposes, including fingerprints, voiceprints, face geometry, or retina or iris scans. If biometric functionality is introduced, separate notices, consent, retention, security, and contractual requirements may apply.
A drawn signature or initials captured through Cordyn Sign is an electronic-signature artifact and is not collected or used as a biometric identifier.
41. BACKGROUND-CHECK INFORMATION
Cordyn is not a consumer-reporting agency or background-check provider unless a specific feature is expressly designed and legally configured for that purpose. Customer remains responsible for Fair Credit Reporting Act and other requirements applicable to any background information it chooses to process.
42. CHILDREN'S PRIVACY
Cordyn is designed for business and organizational use and is not directed to children as consumer users. Users generally must be at least 18 years old or otherwise legally authorized to use the Service on behalf of an organization. Customer-created security or operational records may incidentally include information about minors; Customer is responsible for determining whether that collection and processing is lawful and appropriate.
43. DATA EXPORTS
Authorized Customers may export information from Cordyn. Once data is exported to Customer-controlled systems or disclosed to Customer-authorized recipients, Customer is responsible for protecting those copies. Modul cannot control Customer copies after authorized export.
44. CUSTOMER RESPONSIBILITIES
Cordyn Customers are responsible for:
- Providing required privacy and employee-monitoring notices;
- Obtaining required consent or another lawful basis;
- Determining whether Customer has an appropriate basis to provide signer and counterparty contact information to Cordyn and to send the applicable business transaction, and giving any notices Customer must independently provide to its employees, clients, or counterparties;
- Selecting appropriate signers and determining whether an agreement may be executed electronically;
- Determining appropriate information to collect and retain;
- Configuring roles, permissions, and administrator access;
- Protecting user and integration credentials;
- Responding to privacy requests for Customer-controlled information;
- Establishing retention and deletion requirements;
- Managing authorized integrations and exports;
- Complying with location, biometric, surveillance, employment, and security-licensing requirements; and
- Using Cordyn in accordance with applicable law and contractual obligations.
45. DATA PROCESSING ADDENDUM
Where applicable law requires a written controller-processor, business-service-provider, contractor, or similar data-processing agreement, Modul will enter into or make available a Data Processing Addendum ("DPA") containing the legally required terms, including appropriate instructions, confidentiality, security, subprocessor, rights-request, incident, deletion, and transfer provisions. Customers may request a DPA at privacy@getmodul.app.
If a signed DPA conflicts with this Privacy Policy regarding Customer Data processing, the DPA controls to the extent expressly stated in the DPA.
46. SUBPROCESSORS AND SERVICE PROVIDERS
Modul may use subprocessors and service providers for hosting, databases, backups, authentication, transactional email, monitoring, payment processing, security, customer support, and related technical functions. Modul seeks to use providers appropriate for the services they perform and to establish contractual protections where required by law.
Transactional email for Cordyn Sign is delivered through the same email provider disclosed in this Policy; no separate signature-email vendor is used.
A current subprocessor list may be provided or maintained separately as Cordyn infrastructure evolves. Customers with contractual subprocessor-notice requirements should address those requirements in the applicable DPA or service agreement.
47. THIRD-PARTY SERVICES
This Privacy Policy does not govern third-party websites or services that Customer chooses to integrate with Cordyn or access through external links. Those providers process information under their own terms and privacy practices.
48. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy as Cordyn evolves, our practices change, or legal requirements change. Material changes will be identified by a new version or updated date and may be communicated through Cordyn, email, Customer administrators, or our website. Where appropriate or required, Cordyn may require affirmative acceptance of a revised version.
Cordyn may record the policy version, user, tenant, and acceptance timestamp for versioned legal acceptance.
49. CONTACTING MODUL REGARDING PRIVACY
Modul Development LLC
Cordyn Security Management
Privacy: privacy@getmodul.app
Security: security@getmodul.app
Support: support@getmodul.app
Website: https://cordynhq.com
Please include enough information for us to understand and respond to your request. For security reasons, we may need to verify identity or authority before providing account-specific or personal information.
50. CONTACTING YOUR ORGANIZATION
If your Cordyn account is provided by your employer, security company, client, contractor, or another organization, privacy questions concerning information that organization controls should generally be directed to that organization's Cordyn administrator or privacy contact. Modul may assist the organization where appropriate and legally required.
51. PRIVACY COMMITMENT
Cordyn is designed to handle information important to the security and operations of Customers. Modul seeks to process information only as reasonably necessary to provide, secure, support, and operate Cordyn while preserving Customer control of Customer Data. Customer Data remains Customer's data; use of Cordyn does not transfer ownership of Customer Data to Modul.