1. Who this policy covers
This Privacy Policy explains how PediaSphere ("PediaSphere", "we") collects and uses personal data in three situations:
- Website visitors — people who browse pediasphere.ai or submit the contact form.
- Customer contacts — staff and administrators at organizations that subscribe to PediaSphere.
- End users — members, registrants, and other individuals whose data a Customer organization stores in PediaSphere.
For end-user data, the Customer organization is the controller and decides why and how the data is used; PediaSphere is a processor acting on its instructions under our Data Processing Agreement. If you are a member of a society that uses PediaSphere and have questions about your data, contact that society first; we will assist them in responding.
2. What we collect
2.1 Website visitors
- Contact form: name, work email, organization, product interest, and any message you write.
- Technical data: IP address, browser type, pages viewed, referring page, and timestamps, collected in standard web-server logs.
- Cookies: only those strictly necessary for the site to function. We do not use advertising or cross-site tracking cookies.
- Analytics: we build our own analytics and KPIs inside PediaSphere rather than using third-party analytics tools, to preserve your data privacy. Those analytic results are part of your data stack and belong only to you.
2.2 Customer contacts
- Account details: name, work email, phone (optional), role, organization, and billing contact information.
- Support correspondence: emails you send to support@pediasphere.ai and AI-assisted support exchanges, including the questions asked and answers given.
- Usage data: sign-in events, features used, and audit-log entries recording actions taken in the Service.
2.3 End users (Customer Data)
Customer organizations decide what to store. Typically this includes name, contact details, membership category and status, dues and payment history, event registrations, abstract submissions, committee roles, and — where the organization chooses to collect it — demographic or diversity information. We process this data only as instructed by the Customer.
3. How we use personal data
| Purpose | Data |
|---|---|
| Respond to enquiries and provide quotes | Contact-form data |
| Provide, secure, and support the Service | Customer contact, usage, support, and Customer Data |
| Answer support questions using AI | Support correspondence; scoped, filtered Customer Data |
| Billing and accounting | Billing contact and invoice data |
| Improve the Service and knowledge base | Aggregated usage data; de-identified support themes |
| Security monitoring and audit | Logs, IP addresses, sign-in events |
| Comply with law and enforce our terms | Any of the above as required |
We do not use personal data for advertising, and we do not sell or rent it to anyone.
4. AI and personal data
PediaSphere uses AI to answer support questions and assist with analytics. We apply the safeguards described on our Security page:
- AI requests are scoped to the requesting user's organization and permissions.
- Government identifiers, dates of birth, and payment details are never included in AI prompts.
- Demographic and diversity fields (such as race, ethnicity, gender identity, disability, health, or religion) are excluded at the individual level and reach the AI only as aggregate counts, and only for users whose role permits demographic reporting.
- Neither we nor our AI providers use your data to train or fine-tune models. AI providers are engaged under terms requiring zero data retention beyond the request.
- AI exchanges are logged and a sample is reviewed by our team for quality and safety.
5. Who we share data with
We share personal data only with service providers that help us run PediaSphere, under contracts that restrict their use of the data to our instructions:
| Provider | Purpose | Location |
|---|---|---|
| Microsoft Azure | Hosting, database, storage, backups | |
| Anthropic and OpenAI | AI-assisted support and analytics (zero-retention terms) | |
| PediaSphere mail gateway (built in-house on Microsoft Graph) | Transactional and support email | |
| Your payment processor of choice (PayPal, Stripe, etc.) | Invoicing and card payments (we do not store full card numbers) |
We may also disclose data when required by law, to protect the rights or safety of PediaSphere, our customers, or others, or in connection with a merger or sale of the business (in which case this policy continues to apply and you will be notified).
6. Where data is processed
Personal data is stored and processed in the United States. PediaSphere's team operates from North America, South America, and Western Europe, and support personnel access data only through the Service's access controls and only as needed to help you. Our service providers process data in the locations listed above.
7. How long we keep data
- Contact-form enquiries: 12 months from last contact, then deleted.
- Customer account and billing records: for the life of the subscription plus 7 years for accounting and tax purposes.
- Customer Data (end-user data): for the life of the subscription; deleted from active systems within 90 days after termination, with backups expiring on their normal cycle (30 days).
- Support and AI-exchange logs: 12 months, then deleted or de-identified.
- Security and audit logs: 12 months, longer if needed for an investigation or legal hold.
8. Security
We protect personal data with the measures described on our Security page, including encryption in transit and at rest, passwordless authentication, role-based access, automated backups, and audit logging. No system is perfectly secure; if a breach affecting your data occurs, we will notify affected Customers without undue delay and in any event within the timeframe required by law and the DPA.
9. Your rights
Depending on where you live, you may have the right to know what personal data we hold about you, access it, correct it, delete it, receive a copy in a portable format, and not be discriminated against for exercising these rights. Residents of California and certain other US states have these rights under state privacy laws. We do not sell or "share" personal data as those terms are defined under US state privacy laws.
To exercise these rights, email privacy@pediasphere.ai. We will verify your identity and respond within 30 days (or as required by applicable law). If you are an end user of a Customer organization, we may refer your request to that organization, as it controls your data.
10. Children
The Service is designed for professional organizations and is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us and we will delete it.
11. Changes to this policy
We will post updates here and change the "Last updated" date. For material changes affecting Customers we will also notify the billing contact by email at least 30 days before the change takes effect.
12. Contact
PediaSphere
Phone: +1 737 237 8748 (voicemail; we reply by email)
Privacy enquiries: privacy@pediasphere.ai
Security: security@pediasphere.ai