Legal
Privacy policy
How Rapid Business Integration Solutions Inc. collects, uses, shares, and retains information across its websites and the MITRA platform.
1. Who we are
Rapid Business Integration Solutions Inc. ("RBIS," "we," "us," "our") is a Massachusetts software and IT services company. RBIS operates this website, the MITRA website and applications, and the professional services described elsewhere on this site.
MITRA is a product and platform of RBIS, not a separate legal entity. Where this policy says MITRA, it means that product. Where it says RBIS or "we," it means the company that is legally responsible for the information practices described here. RBIS is the controller (or, under US state privacy laws, the business) for the personal information covered by this policy, except where we act as a processor or service provider for an enterprise customer as described in section 26.
RBIS is registered in Massachusetts, United States. We are a small company operating online, and our registered business address is not published here; we will provide it on request. Our privacy contact is privacy@rapidity.us, and it is the fastest way to reach us about anything in this document, including a request for our postal address.
2. What this policy covers
This policy applies to:
- the RBIS website and the MITRA website;
- the MITRA applications, including the web application and the iOS and Android applications, when they become available to you;
- accounts, membership applications, provider listing applications, careers applications, and other forms we operate;
- communications between you and us about any of the above;
- other services RBIS operates that link to this policy.
Some products and relationships carry additional terms. Where you use MITRA through an enterprise customer, or where RBIS performs professional services under a contract, that agreement (including any data processing agreement) governs the information covered by it, and this policy applies only to the extent it does not conflict. See section 26. The data usage policy describes the website forms in more detail, and the terms of service govern use of the services themselves.
3. The current state of our services
We describe this because a privacy policy that describes a platform you cannot yet use would be misleading about what is actually happening to your information today.
Today, the information practices that are actually operating are the ones in this policy that concern our websites and our forms: the membership early access request, the provider listing application, and the careers application. The MITRA member platform, including its messaging, calendar, profile, and AI features, is in development and is not generally available. Sections of this policy that describe the member platform tell you how it is built to handle information, and they take practical effect for you when you get access to that functionality.
Throughout this policy we try to be explicit about the difference between what we do now, what we may do when a feature becomes available to you, and what would require a separate notice or your consent first.
4. Information you give us
Depending on which of our services you use, this may include:
- Contact and identity details. Your name, a telephone number that you verify with a one-time code, and an email address if you choose to give one. A verified phone number is our primary identifier for people who contact us through our forms.
- Form contents. Whatever you type into a membership, provider, or careers application, including free-text fields, and any links you supply.
- Professional information. Occupation, employer, role, professional background, and similar details, where a form or a profile asks for them.
- Consent records. Which versions of this policy, the terms of service, and the data usage policy you accepted, and when.
- Account and profile information on the member platform. This can include legal and preferred name, username, date of birth, gender, nationality, country of residence, city and region, home address, time zone, language and currency preferences, a short biography, a profile photo and cover image, interests, presence status, a personal website, and links to social media profiles. Most of these fields are optional, and the platform lets you set, field by field, who can see them.
- Content you submit to the platform, as described in section 10.
- Correspondence. Messages you send us, including support and privacy requests, and the information you include in them.
Some of this may be sensitive under applicable law. If we ask for identity verification documents in the future, or if you choose to give us information that is sensitive under the law where you live, we will handle it consistently with section 8 and section 14 and will not use it beyond what is reasonably necessary to provide and secure the service, except with your consent or as the law requires.
5. Information created through your use of MITRA
When the member platform is available to you, using it generates information, including:
- messages and conversations, including conversations with AI agents;
- the prompts, instructions, and context you provide to AI features, and the outputs those features return (see section 9);
- requests you make and the record of how they were handled;
- calendar events and related scheduling information, where you use calendar features;
- preferences and settings, including the per-field visibility choices on your profile;
- audit records of consequential actions, which the platform is designed to write to an append-only log so that there is a reliable record of what happened and who approved it.
Features not currently offered. We do not currently offer general document or file upload, payment or subscription processing, health or wearable data collection, biometric identification performed by us, location tracking, or push notifications. Some of these are designed for and planned in the product. If and when we enable one, we will update this policy and, where the law requires it, give you notice or obtain your consent before that processing begins. Do not read this policy as permission we have already taken for functionality that does not exist.
Biometrics. Where you unlock the MITRA mobile applications with Face ID, Touch ID, or an Android biometric, that check is performed by your device against data held in your device's own secure hardware. Your fingerprint or face data is not transmitted to us and we do not receive or store it. What we receive is the result: that your device confirmed it was you.
Device records. When you register a device to sign in without a password, the applications send us an identifier they generate for that device, along with the public key for the credential. We keep both for as long as that sign-in method is registered, so that we can tell your devices apart, show you which ones have access, and let you remove one. This identifier is created by the application for this purpose. It is not an advertising identifier, we do not use it to track you across other apps or websites, and it is not shared for advertising.
6. Information we collect automatically
- Server and delivery logs. Our content delivery network records requests to our websites, including IP address, timestamp, the resource requested, referring page, and user-agent string. We use these to operate, troubleshoot, and secure the sites, and to detect abuse.
- Application logs. Our backend records events such as sign-in attempts, form submissions, errors, and security-relevant activity, together with identifiers needed to trace a request.
- Device and session information. Session identifiers, authentication tokens, and information about the device and browser you use, to the extent needed to keep you signed in and to protect accounts.
- Security and abuse-prevention signals. We use a web application firewall and rate limiting on our sign-in and form endpoints. These evaluate request patterns and network reputation to block automated abuse.
- On-device storage. Described in section 11.
Our websites do not use analytics, advertising, or cross-site tracking technologies, and they load no third-party resources: fonts and all other assets are served from our own infrastructure, so loading a page does not send a request to another company. We consider the logging described above to be technical and security processing rather than tracking, but we disclose it here rather than describe the sites as collecting nothing.
7. Information we receive from others
- Sign-in providers. If you choose to sign in with Apple or Google, that provider tells us that authentication succeeded and gives us a limited set of identifiers associated with your choice. We do not receive your password.
- Connected services. If you connect a third-party service to MITRA, for example a calendar account, we receive the information that connection is scoped to. You choose whether to connect, and you can disconnect.
- Referrals and introductions. Where someone refers you, or where a provider or partner submits information in connection with you, we may receive your contact details and the context of the referral.
- Providers and partners acting on a request you made, to the extent needed to complete or record it.
- Service providers acting for us, such as security and infrastructure vendors reporting on activity affecting our services.
We do not buy personal information from data brokers, and we do not enrich the information you give us with purchased third-party datasets.
8. How we use information
We use personal information to:
- provide, operate, and maintain our websites, applications, and services;
- create and administer accounts, and verify identity at sign-in;
- respond to your requests, applications, and inquiries, including by telephone;
- personalize what you see, and remember your settings and preferences;
- provide AI features, as described in section 9;
- coordinate services you request through providers you choose, at your direction;
- communicate with you about the services, including service, security, and transactional messages;
- provide customer and member support;
- secure our services, authenticate users, and prevent, detect, and investigate fraud, abuse, spam, and security incidents;
- debug, monitor, measure reliability, and improve our services;
- maintain audit and compliance records;
- comply with legal obligations and respond to lawful requests;
- establish, exercise, and defend legal claims, and enforce our agreements;
- administer our business, including accounting, billing where applicable, and internal reporting;
- maintain backups and provide for disaster recovery;
- evaluate, negotiate, or complete a corporate transaction as described in section 24.
We do not use member content to advertise to you, and we do not currently run any advertising or marketing analytics program.
Calls and texts. By providing your telephone or wireless number, you agree to receive calls and texts from us (including prerecorded or artificial voice messages and autodialed calls and texts) at the telephone or wireless number provided.
That agreement is limited to operational contact, and we hold it to that limit. We use your number to verify who you are, to reach you about a request or an application you made, and to send service, security, and transactional messages. The reason the agreement above names automated delivery is that a one-time sign-in code is itself an automated text, not that we intend to run a calling campaign. We do not send marketing calls or marketing texts, and we do not send marketing email. If that ever changes we will ask you for separate consent before it does, because this agreement does not cover it. Your mobile carrier's message and data rates may apply. This is a consent you give us, so the withdrawal right described immediately below applies to it: tell us to stop and we will stop.
We do not share, sell, or provide your mobile phone number or messaging consent to any third party or affiliate for their own marketing or promotional purposes. The service providers named in section 13 receive your number only to deliver a message on our behalf, such as the vendor that transmits the SMS itself, and are contractually bound to use it for that purpose only.
Legal bases. Where the law that applies to you requires a legal basis for processing, we generally rely on: performance of a contract with you, or steps taken at your request before entering one; our legitimate interests in operating, securing, and improving our services and in preventing fraud and abuse, where those interests are not overridden by your rights; your consent, where we ask for it, including the versioned policy acceptance recorded on our forms; and compliance with legal obligations. Where we rely on consent, you may withdraw it at any time, which does not affect processing carried out before you withdrew it.
9. AI, machine learning, and automated processing
MITRA is designed as an AI platform, so we describe this separately and in detail.
How AI features work. When you use an AI feature, the input you provide, and context the platform assembles to answer you (which may include information from your account and from earlier messages in the same conversation), is submitted to a large language model. The model returns a response, which is shown to you and may be stored as part of the conversation. Prompts, responses, and the fact that a model was called are recorded in our logs and audit trail so that there is a record of what the system did.
Third-party AI providers. MITRA is built to work with more than one AI provider rather than being tied to a single one. When a feature is served by a third-party model, your input and the assembled context are transmitted to that provider, which processes them on our behalf as a service provider or subprocessor in order to generate the response. That provider's own terms govern how it handles what it receives, including whether it retains inputs and outputs and for how long. We will name the AI providers in use, and the controls that apply to them, in the subprocessor information described in section 13 as those providers are put into production.
What we can tell you today. No AI feature of MITRA is generally available, and we are not currently transmitting member content to any third-party AI provider in production. The platform's default configuration uses a local simulated model that makes no external call. Before we enable a third-party AI provider for member content, we will identify it and describe the applicable retention and training controls.
Training. RBIS does not build or train its own AI models, and we do not use your content to do so. We do not provide member content to any third party for the purpose of training that third party's models. We cannot, and do not, make an unconditional promise about every provider's practices for all time: what a provider is permitted to do with data it receives is set by our contract with that provider, and where a provider's standard terms would permit training on inputs, we will either configure the service to prevent it, contract for its exclusion, or disclose it here before that provider processes member content. We may use your content to evaluate and improve our own service, including reviewing outputs for quality, safety, and abuse, in line with section 8 and section 10.
Storage and deletion of AI conversations. Conversations, including prompts and AI responses, are stored so that the service can show you your history and so that we can meet the audit obligations described in this policy. Self-service deletion of individual conversations is not available today. You can ask us to delete conversation content under section 16, subject to the limits described there. We will describe self-service controls here when they ship.
AI outputs are not guaranteed. AI systems produce text by prediction. Outputs may be inaccurate, incomplete, outdated, biased, or otherwise unexpected, and they may be confidently wrong. You are responsible for reviewing AI-generated output before relying on it or acting on it. AI output is not professional advice of any kind (see section 29).
Automated decisions. We do not use AI or other automated processing to make decisions that produce legal effects concerning you or similarly significantly affect you without human involvement. Automated systems do score and order inbound inquiries for follow-up, and security systems automatically block traffic that looks abusive. MITRA is designed so that consequential actions, meaning those touching money, health information, or an irreversible booking, require your explicit confirmation before they are carried out, and an AI agent alone is not designed to be able to complete one. If we introduce automated decision-making of the kind that triggers additional rights under the law that applies to you, we will describe it here and honor those rights.
10. Your content
You own your content. As between you and RBIS, you keep all rights in the messages, files, and other material you submit to the services. We do not claim ownership of it.
You grant us a limited, non-exclusive, worldwide, royalty-free license to host, store, copy, transmit, display, process, and create technical derivatives of your content solely as needed to operate and secure the services, to provide the functionality you request, and to comply with law. This license lasts only as long as we hold your content for those purposes, and it exists so that ordinary operations such as transmitting a message, indexing it so you can search it, sending it to an AI provider so a feature can answer you, and backing it up are lawful. It does not permit us to use your content to advertise to you or to sell it.
To operate the service we and our providers store your content, back it up, restore it after failures, and apply security controls to it. Personnel access to member content is limited to what is needed to run the service, respond to a support request you make, investigate a security or abuse problem, or comply with a legal obligation, and such access is logged. Content may also be preserved beyond a deletion request where a legal hold, an investigation, or an audit obligation requires it, as described in sections 15 and 16.
11. Cookies and similar technologies
Our websites set no advertising or analytics cookies, and perform no cross-site or cross-context tracking. What they do use is limited to what makes the site work:
- Local storage: a record that you have seen our cookie and storage notice, and your light or dark theme preference.
- Session storage: during the sign-in flow used by our forms, a short-lived token proving your verified phone number, the security value that protects that sign-in exchange, and the page to return you to. These are discarded when your browser session ends.
None of this is shared with another company, and none of it follows you to other websites. If you block storage in your browser, the sites still work; the notice simply reappears. The MITRA applications store authentication material in your device's secure storage rather than in cookies. Separately from on-device storage, our servers and content delivery network keep the logs described in section 6.
12. How we share information
We do not disclose your information except as described in this policy. Specifically, we may disclose it:
- at your direction, including to providers you ask us to engage and to people you choose to share with through the platform;
- to service providers and subprocessors that process information on our behalf, as described in section 13;
- to professional advisers, such as lawyers, accountants, auditors, and insurers, where reasonably necessary and under duties of confidentiality;
- for legal and safety reasons, as described in section 27;
- in a corporate transaction, as described in section 24;
- in aggregated or de-identified form, as described in section 28;
- with your consent, for anything else.
Where we disclose information because the law compels it, we will tell you unless we are prohibited from doing so or unless doing so would be unreasonable in the circumstances, for example where there is a risk to someone's safety.
13. Service providers and subprocessors
Like most software companies, we rely on third parties to run our services. They act on our instructions, are bound by contract, and receive only the information reasonably necessary for the function they perform. We use, or expect to use, providers in these categories:
- cloud hosting, storage, content delivery, and networking;
- databases and backup;
- identity, authentication, and one-time-code delivery, including SMS delivery;
- AI and large language model processing (see section 9);
- email delivery for operational and security notices;
- logging, monitoring, error reporting, and security tooling;
- payment processing, if and when we charge for a service;
- customer and member support tooling;
- professional and business administration services.
Today, our production infrastructure runs on Amazon Web Services in the United States, and SMS delivery of sign-in codes runs through that provider. We will publish and maintain a current list of the subprocessors that process personal information, and we will make it available on request from privacy@rapidity.us in the meantime. Maintaining that list separately from this policy is deliberate: a subprocessor can change without the substance of this policy changing.
14. Sale, sharing, and targeted advertising
These words have specific meanings under US state privacy laws, so we use them carefully rather than saying simply that we do not share data, which would be inaccurate given that vendors process information for us.
- We do not sell personal information for money or other valuable consideration.
- We do not share personal information for cross-context behavioral advertising, and we do not engage in targeted advertising. We operate no advertising program.
- We do not use personal information for profiling in furtherance of decisions that produce legal or similarly significant effects.
- We do disclose personal information to service providers and contractors that process it for us under contract, as described in section 13. Under US state privacy laws this is a disclosure for a business purpose, not a sale or a share.
- We do disclose information at your direction, and where the law requires it.
If this ever changes, we will update this policy and provide any opt-out mechanism the law requires before the change takes effect.
15. Retention
We keep personal information for as long as reasonably necessary for the purposes described in this policy, and then delete it or de-identify it. How long that is depends on the information and the purpose. In deciding, we consider how long we need it to provide the service, whether we need it to resolve a dispute or enforce our agreements, whether a law or a tax, accounting, or audit obligation requires us to keep it, and the risks of keeping it against the risks of losing it.
Specific periods we can state today:
- content delivery network access logs are deleted automatically 90 days after they are written;
- application logs are retained for six months;
- saved but unsubmitted form drafts expire automatically after 30 days;
- submitted inquiries and applications are retained until we delete them, including on your request, rather than on a fixed automatic schedule. We are working toward a defined schedule for inquiries that do not proceed and will state it here when it is in place;
- records of the policy versions you accepted are kept for as long as we may need to evidence that acceptance;
- account and member content is retained while your account is open, and afterward as described in section 16.
Information may persist in encrypted backups and disaster-recovery copies after it is removed from our live systems, and is deleted or overwritten as those copies age out on their normal cycle. Information subject to a legal hold is retained until the hold is lifted.
16. Deletion
You can ask us to delete personal information we hold about you by writing to privacy@rapidity.us. We will verify your request as described in section 19 and act on it within the time the applicable law allows.
We will delete or de-identify what we can, but deletion is not unlimited and we will not promise you that it is. We may retain information where it is reasonably necessary to:
- comply with a legal, regulatory, tax, accounting, or audit obligation;
- comply with a legal hold, or to establish, exercise, or defend legal claims;
- detect, prevent, and investigate security incidents, fraud, and abuse, and to maintain the integrity of our security and audit records;
- resolve a dispute or enforce our agreements;
- maintain business records we are entitled to keep;
- honor a request you made, for example to be excluded from future contact, which requires keeping enough information to recognize you.
Content in another person's copy of a shared conversation, and content already delivered to a provider at your direction, may not be within our power to remove. Deleted information may remain in backups for a period after removal from live systems, as described in section 15. Where we cannot delete something, we will tell you why, and we will restrict its use to the purpose that justifies keeping it.
17. Security
We maintain administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, use, disclosure, alteration, and destruction, taking into account the nature of the information and the risks involved. These currently include:
- encryption of traffic in transit using TLS, and encryption of stored data at rest by our cloud provider;
- authentication designed around verified phone numbers and, on the member platform, hardware-backed keys held in the secure hardware of your own device, with biometric unlock performed on the device;
- access controls that scope each part of the system to the data it needs, and separation of environments and of data belonging to different product domains;
- a web application firewall, rate limiting, and abuse detection on sign-in and form endpoints;
- logging and monitoring, with automated alerting on failures in our request pipeline;
- audit logging designed to record consequential actions in an append-only form;
- a design requirement that consequential actions carry an explicit confirmation step.
Some of the controls described in our engineering documentation apply to functionality that is not yet generally available. We have tried to keep this section to what is in place, and we do not represent that a control that is planned is already protecting your information.
RBIS has not obtained a SOC 2 report, ISO 27001 certification, or any comparable third-party security certification or attestation, and we do not claim compliance with any such framework. Our security page describes the architecture in plain language and states our current status.
No method of transmitting or storing information can be guaranteed to be completely secure, and we cannot and do not guarantee the security of information you transmit to us or that we hold. Where the law requires us to notify you or a regulator of a security breach involving your personal information, including under Massachusetts General Laws chapter 93H, we will do so as that law requires.
This policy is a public description of our practices. It is not, and does not substitute for, the internal information security program, incident response procedures, and vendor security requirements that we maintain separately and that are not published.
Your part. Keep your device, your credentials, and your account secure, and tell us promptly at privacy@rapidity.us if you believe someone has gained unauthorized access to your account. Nothing here shifts to you an obligation that the law places on us.
18. Your privacy rights
Depending on where you live and which law applies, you may have the right to:
- know what personal information we collect, use, disclose, and retain, and why;
- access a copy of the personal information we hold about you;
- correct inaccurate personal information;
- delete personal information, subject to section 16;
- obtain a portable copy of information you provided to us, where technically feasible;
- opt out of the sale of personal information, of sharing for cross-context behavioral advertising, and of certain profiling. We do not carry out any of these, so there is nothing to opt out of, but you may still submit a request and we will confirm that position;
- limit the use and disclosure of sensitive personal information, where that right applies;
- withdraw consent, where we relied on consent;
- object to or restrict certain processing, where that right applies;
- not be discriminated against for exercising a privacy right;
- appeal a decision we make on your request, where the applicable law provides an appeal.
Which of these you actually have is set by the law that applies to you, and some of these laws apply to a company only above certain thresholds. We do not assert that every law is applicable to RBIS. As a matter of policy, we accept and act on access, correction, and deletion requests from anyone who contacts us, whichever law does or does not apply, subject to the verification step in section 19 and the limits in section 16.
19. Exercising your rights, and how we verify them
Write to privacy@rapidity.us and tell us what you are asking for. If you have used our forms, mentioning your verified phone number helps us find your record.
Verification. Before we act on a request, we take reasonable steps to confirm that it comes from you or from someone you have authorized. What we ask for depends on the sensitivity of the request: confirming control of the phone number or email address associated with the record is typical, and a request to access or delete more sensitive information may need more. We will not disclose personal information to a requester we cannot reasonably verify, and we may decline a request on that basis. Information we collect to verify a request is used only for that purpose and for our record of having handled it.
Authorized agents. Where the applicable law permits, an authorized agent may submit a request for you. We may ask the agent for proof of authorization, and we may ask you to verify your own identity with us directly or to confirm that you gave the agent permission.
Timing and outcome. We respond within the period the applicable law sets, and we will tell you if we need an extension the law allows. If we decline a request in whole or in part, we will tell you why, and we will tell you how to appeal where the applicable law provides an appeal. There is no charge for a reasonable request; we may charge a reasonable fee, or decline, where a request is manifestly unfounded, excessive, or repetitive, to the extent the law permits.
You will not be denied service, charged a different price, or given a different level of quality because you exercised a privacy right.
20. California residents
This section applies to California residents where the California Consumer Privacy Act, as amended by the California Privacy Rights Act, applies to our processing of your information. We provide the following disclosures without conceding that any particular threshold for applicability is met.
The categories of personal information we may collect are described in sections 4 through 7. In the terms the statute uses, these correspond to identifiers; personal information listed in the California customer records statute; characteristics of protected classifications, where you choose to provide them; commercial information; internet or other electronic network activity information; professional or employment-related information; and inferences drawn from the foregoing. To the extent information such as precise nationality, or the contents of your messages, is treated as sensitive personal information, we use and disclose it only for purposes the statute permits without an option to limit, meaning to provide the service you requested, to secure it, and for the other permitted business purposes described in this policy. The sources, purposes, and disclosure practices for each category are described in sections 4 through 8 and 12 through 14. Retention is described in section 15.
We have not sold personal information or shared it for cross-context behavioral advertising, and we have no actual knowledge of selling or sharing the personal information of consumers under 16 years of age. California residents may exercise the rights to know, access, correct, delete, and limit as described in sections 18 and 19, including through an authorized agent, without discrimination.
21. Other US states
Residents of other states with comprehensive consumer privacy laws, including Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, and others as those laws come into force, have rights of the kind described in section 18 where the applicable law applies to us. This includes, in most of those states, a right to appeal a refusal of a request, and a right to contact the state attorney general if the appeal is unsuccessful. Submit requests and appeals to privacy@rapidity.us.
Because we do not sell personal information, do not process it for targeted advertising, and do not engage in profiling that produces legal or similarly significant effects, the opt-out rights those laws provide do not currently have anything to operate on. We do not recognize a universal opt-out preference signal today, because there is no processing for it to control; if that changes, we will honor those signals where the law requires and will say so here.
22. Users outside the United States
RBIS is a United States company and our infrastructure is located in the United States. Our services are directed to users in the United States. If you access them from elsewhere, you do so on your own initiative, and the information you provide is transferred to and processed in the United States, where privacy laws differ from those in your country and where government authorities may be able to access information under United States law.
We are not claiming compliance with the General Data Protection Regulation, the UK GDPR, the Swiss Federal Act on Data Protection, Canada's PIPEDA, Brazil's LGPD, India's Digital Personal Data Protection Act, or any other non-US framework. We have not appointed an EU or UK representative or a data protection officer, and we have not put in place a standalone international data transfer mechanism of our own; for transfers carried out by our infrastructure providers we rely on the terms those providers make generally available in their data processing agreements. Before we offer the services into a market where one of those frameworks applies to us, we will put the required arrangements in place and describe them here.
In the meantime, if you are outside the United States you may have rights under the law where you live. Write to privacy@rapidity.us. We handle requests from outside the United States the same way we handle requests from inside it, as described in sections 18 and 19, and we will tell you honestly where we cannot offer something that a local framework would otherwise require.
23. Children
Our websites and MITRA are intended for adults. They are not directed to children, and we do not knowingly collect personal information from anyone under 18. If you believe a child has provided us with personal information, write to privacy@rapidity.us and we will delete it.
MITRA is designed to include family features, and some of those could involve information about minors. We will not enable any feature that collects personal information from or about a minor until it has had a separate privacy and legal review, and until this policy has been updated to describe it and, where required, verified parental consent has been obtained.
24. Business transfers
If RBIS is involved in a merger, acquisition, financing, due diligence, reorganization, restructuring, sale of all or part of its assets or business, bankruptcy, receivership, or other change of control, personal information may be reviewed by, and transferred to, the parties to that transaction and their advisers, subject to confidentiality protections appropriate to the stage of the transaction. If personal information is transferred and becomes subject to a different privacy policy, we will notify you as the applicable law requires.
25. Third-party sites and services
Our websites and applications may link to, or let you connect to, services operated by other companies. Those services are controlled by them, not by us. Their handling of your information is governed by their own privacy policies, and we are not responsible for their practices. Review the privacy policy of any service before you use it or connect it, and manage what you have connected through that service's own controls as well as ours.
26. Enterprise customers and professional services
RBIS provides software and IT services to businesses as well as operating MITRA. Where an organization is our customer, the relationship works differently from the consumer relationship this policy otherwise describes.
Where an organization provides MITRA or another RBIS service to its own personnel or customers, that organization generally determines what information is processed and why. In that arrangement the organization is the controller or business, and RBIS acts as its processor or service provider under the agreement between us. That agreement, including any data processing agreement, governs subprocessors, retention, deletion, security commitments, breach notification, audit, and the handling of customer data and employee data, and it takes precedence over this policy for the information it covers. If you are a user within such an organization, direct your privacy requests to that organization first; if you contact us, we will generally refer you to them and assist them in responding.
Where RBIS performs professional services under a statement of work, the contract, together with any data processing agreement, security addendum, and confidentiality agreement, sets the requirements for information we handle in that engagement.
We do not apply consumer-facing terms of this policy to an enterprise relationship where a contract governs the same subject matter, and we do not use a contract to reduce rights that applicable law gives an individual directly.
27. Legal and regulatory disclosures
We may access, preserve, and disclose information where we reasonably believe it is necessary to:
- comply with applicable law, regulation, legal process, or an enforceable governmental request;
- respond to a subpoena, court order, warrant, or similar lawful demand;
- enforce our terms and other agreements, including investigating potential violations;
- detect, prevent, or address fraud, security, abuse, or technical issues;
- protect the rights, property, or safety of our users, of RBIS, or of the public, including in an emergency involving a risk of death or serious physical injury;
- establish, exercise, or defend legal claims.
We review demands for information and, where we consider a demand improper or overbroad, we may challenge it. Where we are permitted to notify you of a demand for your information, our practice is to do so.
28. Aggregated and de-identified information
We may create aggregated, statistical, or de-identified information from the information we hold, and use and disclose it for any lawful purpose, including operating, analyzing, and improving our services and describing them publicly. Where we hold information in de-identified form, we maintain it in that form, do not attempt to re-identify it except to test the effectiveness of our de-identification or as the law otherwise permits, and require the same of recipients by contract.
We describe such information as de-identified or aggregated rather than anonymous, because de-identification is a matter of degree and we do not claim that re-identification is impossible.
29. No regulated professional advice
RBIS is a software and services company. It is not a registered investment adviser, a broker-dealer, a bank, an insurance producer, a law firm, a tax adviser, or a healthcare provider, and it is not acting in any of those capacities when you use our services. Nothing produced by MITRA, including AI-generated output, is financial, investment, tax, legal, insurance, medical, or other regulated professional advice, and none of it should be relied on as a substitute for a licensed professional. Where a service is delivered by a licensed provider through the platform, that provider is responsible for the regulated advice it gives, under its own terms and its own regulator. The fact that we may process financial, health-adjacent, or other regulated categories of information does not make RBIS a regulated financial, health, or professional services firm, and does not create a fiduciary, advisory, or professional relationship between us.
30. Changes to this policy
We may update this policy as our services, our providers, and the law change. Every version carries a version identifier and, once in force, an effective date, both shown at the top of this page.
Changes generally apply going forward from the date the updated version takes effect. If we make a material change, we will take steps reasonably designed to bring it to your attention before it applies to you: our forms ask prospective members to review and accept the current version before their next submission, and we will notify account holders in the application or by a service message. Where the law requires your consent to a particular change, we will obtain it. Where it does not, continued use of the services after an update takes effect means the updated policy applies to that use, to the extent the law permits.
31. Contact us
For any privacy question, or to exercise a right described in this policy, write to privacy@rapidity.us. This is the address to use, and we monitor it.
Rapid Business Integration Solutions Inc., Massachusetts, United States. Our registered business address is available on request from the address above. MITRA is a product of Rapid Business Integration Solutions Inc.
If you are in a jurisdiction with a data protection authority and you are not satisfied with our response, you may be entitled to complain to that authority.