Privacy Policy — C-Suite Coaching OS
Important — Who Handles Your Data

C-Suite Coaching OS is operated by PitchTank AI, which is the data controller responsible for processing your information. C-Suite Network™ is a brand and distribution partner only — C-Suite Network™ does not collect, store, access, or process any of your account data, User Content, or personal information.

01Who We Are

PitchTank AI ("Company," "we," "us," or "our") operates C-Suite Coaching OS (the "Service") and is the data controller for your information collected through the Service.

C-Suite Coaching OS is offered and marketed under the C-Suite Network™ brand through a licensing arrangement. C-Suite Network™ is not a data processor, data controller, or recipient of your data. All data collected through the Service flows exclusively to PitchTank AI and the service providers we use to operate the Service.

This Privacy Policy applies to information collected through the Service. It does not apply to data collected by C-Suite Network™ through its other websites or programs.

02Information We Collect

Account Information

When you register for the Service, we collect:

  • Your name and email address;
  • Your business name and role (optional);
  • Billing information processed by Stripe (we do not store full payment card details);
  • Account login credentials.

User Content

The Service allows you to upload documents and input information for analysis ("User Content"), which may include client documents, financial information, business plans, strategic materials, and other content you choose to share with the Service. We collect and process this User Content solely to provide the Service to you.

Usage Data

We automatically collect technical and usage information when you use the Service, including:

  • Device information (browser type, operating system, device type);
  • IP address and approximate location;
  • Session information (login times, features used, session duration);
  • Log data (actions taken in the Service, error reports);
  • Referring URL and pages visited.

Communications

When you contact us for support or otherwise communicate with us, we collect the contents of those communications and any information you choose to provide.

03How We Use Your Information

We use the information we collect to:

  • Provide, operate, and maintain the Service;
  • Process your subscription and payments through Stripe;
  • Authenticate your account and prevent unauthorized access;
  • Generate AI-based analyses, recommendations, and deliverables based on your inputs;
  • Respond to your support requests and communicate with you about the Service;
  • Improve the Service's reliability, performance, and security (using aggregated, anonymized usage data only);
  • Detect, investigate, and prevent fraudulent, unauthorized, or illegal activity;
  • Comply with legal obligations and enforce our Terms.

04AI Training & Your Data

Because the Service is used for sensitive business work — including client information and confidential strategy — we follow strict practices regarding AI training data:

We do not use your User Content to train AI models. Your prompts, uploaded documents, and the Service's outputs to you are not used to train, fine-tune, or improve any AI model — ours or any third party's.

Specifically:

  • We do not train our reasoning frameworks or models on your inputs or outputs;
  • We do not share your User Content with AI model providers for the purpose of training their models;
  • Our agreements with underlying AI/LLM providers prohibit them from using your data to train their models;
  • Your User Content is processed solely to generate the output you've requested, then handled according to our data retention policy.

05How We Share Information

We share information only as described below. We do not sell your personal information or User Content to third parties.

Service Providers

We share limited information with service providers that help us operate the Service, including:

  • Stripe — for payment processing;
  • Cloud hosting providers — for infrastructure and storage;
  • AI/LLM providers — to process Service prompts and generate output (under contractual restrictions that prohibit training on your data);
  • Email and communication services — for transactional communications;
  • Security and fraud detection services — to protect the Service and our users.

All service providers are bound by contractual obligations to use your information only as necessary to provide their services to us.

Legal Requirements

We may disclose information if required by law, court order, or government request, or if we believe disclosure is necessary to protect our rights, prevent fraud, or protect the safety of others.

Business Transfers

If we are involved in a merger, acquisition, sale of assets, or similar transaction, your information may be transferred as part of that transaction. We will notify you and the transferee will be required to honor this Privacy Policy.

What We Don't Share

We do not share your information with:

  • C-Suite Network™ (the brand partner) — C-Suite Network™ has no access to your data;
  • Advertisers or marketing networks;
  • Data brokers;
  • Other users of the Service.

06Cookies & Tracking

The Service uses cookies and similar technologies for the following purposes:

Essential Cookies

Required for the Service to function — authentication, session management, security. These cannot be disabled.

Analytics Cookies

We use analytics tools to understand how the Service is used in aggregate. This data is anonymized and used only to improve the Service.

What We Don't Use

We do not use advertising cookies, behavioral tracking cookies, or third-party marketing cookies.

You can control cookies through your browser settings. Disabling essential cookies will prevent the Service from functioning properly.

07Data Security

We use industry-standard security measures to protect your information, including:

  • Encryption in transit (TLS) for all data transmitted to and from the Service;
  • Encryption at rest for stored data;
  • Access controls limiting employee and contractor access to data on a need-to-know basis;
  • Regular security reviews and updates;
  • Secure cloud infrastructure provided by reputable hosting partners.

Despite these measures, no method of transmission or storage is completely secure. We cannot guarantee absolute security and recommend you use the Service in accordance with security best practices, including using strong passwords and not sharing your credentials.

08Data Retention

We retain your information for as long as necessary to provide the Service and fulfill the purposes described in this Privacy Policy. Specifically:

  • Account information is retained for as long as your account is active.
  • User Content is retained while your account is active. You can delete specific User Content from your account at any time.
  • Upon cancellation, your account data and User Content are retained for 30 days to allow reactivation. After 30 days, the data is permanently deleted.
  • Transaction and billing records are retained for the period required by applicable tax and accounting laws (typically seven years).
  • Anonymized and aggregated data used for analytics may be retained indefinitely as it cannot be used to identify you.

09Your Privacy Rights

You have the following rights regarding your information:

  • Access — request a copy of the personal information we hold about you;
  • Correction — request correction of inaccurate or incomplete information;
  • Deletion — request deletion of your information (subject to legal and contractual obligations);
  • Portability — receive your information in a structured, machine-readable format;
  • Objection — object to certain processing activities;
  • Restriction — request limitation of how your data is processed;
  • Withdrawal of consent — withdraw consent where consent is the legal basis for processing.

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days. We may need to verify your identity before processing requests.

10GDPR Rights (EEA Users)

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have additional rights under the General Data Protection Regulation (GDPR).

Legal Basis for Processing

We process your personal data on the following legal bases:

  • Performance of a contract — to provide the Service you subscribed to;
  • Legitimate interests — to operate, secure, and improve the Service;
  • Legal obligations — to comply with tax, accounting, and regulatory requirements;
  • Consent — where you have explicitly consented to processing.

Right to Lodge a Complaint

You have the right to lodge a complaint with your local data protection authority if you believe your rights have been violated.

11CCPA Rights (California Users)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

  • The right to know what personal information we collect, use, disclose, and (if applicable) sell;
  • The right to request deletion of your personal information;
  • The right to correct inaccurate personal information;
  • The right to opt out of the sale or sharing of personal information (note: we do not sell or share personal information);
  • The right to limit use of sensitive personal information;
  • The right to non-discrimination for exercising your CCPA rights.

To exercise your California rights, contact us at [email protected].

12Children's Privacy

The Service is intended for business use by adults and is not directed at children. We do not knowingly collect personal information from anyone under 18 years of age. If we learn we have collected information from a person under 18, we will delete it promptly. If you believe a minor has provided us with personal information, please contact us at [email protected].

13International Data Transfers

PitchTank AI is based in the United States. If you access the Service from outside the United States, your information will be transferred to, stored, and processed in the United States, where data protection laws may differ from those in your country.

For transfers from the EEA, UK, or Switzerland, we rely on Standard Contractual Clauses or other approved transfer mechanisms with our service providers to ensure appropriate safeguards are in place.

14Third-Party Services

The Service uses third-party services to operate. These services have their own privacy practices, which we encourage you to review:

  • Stripe (payment processing) — stripe.com/privacy
  • Cloud infrastructure providers — operating under enterprise data processing agreements;
  • AI/LLM providers — operating under data processing agreements that prohibit training on customer data.

The Service may also link to or embed content from third-party websites. We are not responsible for the privacy practices of those third parties.

15Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, the Service, or applicable law. When we make material changes, we will notify you by email and/or by posting a prominent notice in the Service at least 30 days before the changes take effect.

The "Effective" date at the top of this policy indicates when it was last updated. Your continued use of the Service after the effective date constitutes acceptance of the updated Privacy Policy.

16Contact

If you have questions about this Privacy Policy, want to exercise your privacy rights, or need to report a privacy concern, contact PitchTank AI directly:

PitchTank AI
Email: [email protected]

For questions about C-Suite Network™ as a brand, you may contact C-Suite Network™ directly, but note that C-Suite Network™ does not have access to your account data, User Content, or other information collected through the Service, and cannot respond to privacy requests on behalf of PitchTank AI.