Privacy Policy
Last updated: June 29, 2026
This document is a starter template provided for convenience. It is not legal advice and must be reviewed and adapted by qualified legal counsel before you rely on it.
Your privacy matters to us. This policy describes what information Palette collects, how we use it, and the choices you have. Please read it alongside any agreement your organization has with us.
1. Who We Are
Palette is operated by Palette Technology, Inc. ("Palette", "we", "us"). This Privacy Policy explains how we collect, use, and protect information when you visit our website, request a demo, or use our platform.
Palette provides an AI-native HR operating system that our customers use to manage their people operations. This policy distinguishes between information we collect about website visitors and prospects, where Palette is the controller, and the HR and employee data our customers entrust to us, where Palette acts as a processor.
2. Website Visitors and Customer Data
We handle two different kinds of information differently:
- Visitor and prospect data: information about people who visit our website, book a demo, or contact us. Palette decides how this data is used and is the controller for it.
- Customer data: HR and employee data that a customer loads into the platform. The customer is the controller and decides how it is used. Palette processes it on the customer's behalf and under their instructions, and is the processor for it.
- If you are an employee of one of our customers and have questions about your data, please contact your employer, who controls that data.
3. Information We Collect
We collect the following categories of information:
- Information you provide: your name, work email, company, phone number, and anything you share when you book a demo or contact us.
- Usage information: pages visited, referring links, device and browser details, and similar analytics collected automatically when you use our website.
- Customer data: when a customer uses our platform, we process the HR and employee data they choose to load, on their behalf and under their instructions.
4. How We Use Information
As a controller for visitor and prospect data, we use it to:
- Provide, operate, secure, and improve our website and platform.
- Respond to demo requests, support inquiries, and other communications.
- Understand how our website is used so we can make it better.
- Comply with legal obligations and enforce our agreements.
5. Legal Bases for Processing
Where the GDPR or similar laws apply to our processing of visitor and prospect data, we rely on the following legal bases:
- Performance of a contract, to provide the services or respond to your requests.
- Legitimate interests, to operate, secure, and improve our website and business, balanced against your rights.
- Consent, where required, for example for certain cookies or marketing, which you may withdraw at any time.
- Legal obligation, to comply with applicable law.
6. AI Processing
Our platform uses artificial intelligence to generate recommendations, workflows, analyses, and other outputs. We want to be clear about how that works:
- We do not use Customer Data to train public foundation models, unless a customer instructs us otherwise in writing.
- Prompts and related context are processed only to generate outputs and operate the service, under the same confidentiality and security commitments as other Customer Data.
- We send data to AI model providers only as needed to deliver features, under contracts that prohibit them from using it to train their general models. Our subprocessor page lists the providers involved.
- AI outputs can be inaccurate or incomplete and should be reviewed by a person before being relied upon for decisions about individuals.
7. How We Share Information
We do not sell your personal information and do not share it for cross-context behavioral advertising. We share information only in these limited circumstances:
- Service providers and sub-processors that help us run the business, such as hosting, AI model, analytics, and email providers, under contracts that require them to protect it.
- Legal and safety reasons, when required by law or to protect our rights, users, or the public.
- Business transfers, such as a merger, acquisition, or sale of assets, with notice where required.
8. Cookies and Analytics
We use cookies and similar technologies to operate our website, remember preferences, and measure usage. You can control cookies through your browser settings, though some features may not work without them. Where required, we obtain consent before setting non-essential cookies.
9. International Data Transfers
We may process and store information in the United States and other countries. Where we transfer personal data from the European Economic Area, the United Kingdom, or Switzerland, we use appropriate safeguards such as the European Commission's Standard Contractual Clauses, together with supplementary measures where needed.
10. Data Retention
We keep personal information only as long as needed for the purposes described in this policy, to comply with legal obligations, resolve disputes, and enforce our agreements. Customer Data is retained according to the customer's agreement and instructions, and is deleted or returned on termination as described in our Data Processing Addendum.
11. Data Security
We use administrative, technical, and organizational measures designed to protect information against unauthorized access, loss, or misuse, including encryption in transit and at rest, access controls, and logging. You can read more on our security page. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
12. Your Rights and Choices
Depending on where you live, you may have rights to access, correct, delete, port, or restrict the use of your personal information, or to object to certain processing. Under the CCPA, California residents may request to know, delete, and correct personal information and may opt out of sale or sharing, though we do not sell or share personal information. Under the GDPR, you may also lodge a complaint with a supervisory authority.
To exercise these rights for data we control, contact us using the details below. We will not discriminate against you for exercising them. If your request concerns data a customer controls, we will refer you to that customer or assist them in responding.
13. Children's Privacy
Our website and platform are intended for businesses and are not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us personal information, please contact us so we can delete it.
14. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "last updated" date above and, where appropriate, provide additional notice.
15. Contact Us
If you have questions about this Privacy Policy or our data practices, contact us at founders@palettetechnology.com or (408) 889-1158.

