Privacy Policy

Effective Date: 23 NOVEMBER 2025 
Last Updated: 17 APRIL 2026

This Privacy Policy (“Policy”) describes how Greypike, Inc. (“Greypike,” “Company,” “we,” “us,” or “our”) collects, uses, discloses, and protects information in connection with our website at www.greypike.com, the Obolix compliance platform, the Greypike client portal, and any related products or services (collectively, the “Services”).

By accessing or using the Services, you acknowledge that you have read and understood this Policy. If you do not agree with this Policy, do not use the Services.

1. Scope

This Policy applies to personal information we collect through the Services. It does not apply to:

  • Information our clients process through the Services in their capacity as data controllers (that information is governed by the applicable Master Services Agreement, Data Processing Addendum, or equivalent contract);
  • Third-party websites, applications, or services that link to or from our Services; or
  • Information collected offline or through channels not described in this Policy.

For information processed on behalf of a client (including Controlled Unclassified Information (“CUI”)), Greypike acts as a service provider, processor, or subcontractor. The client’s own privacy notices and agreements govern that processing.

2. Information We Collect

2.1 Information You Provide to Us

We collect information you voluntarily provide, which may include:

  • Identifiers: first and last name, email address, postal address, telephone number, and employer or job title.
  • Account information: username, authentication credentials (stored in hashed form), and security questions or multi-factor authentication data.
  • Commercial information: records of products or services purchased or inquired about.
  • Communications: content of emails, support tickets, chat messages, and other correspondence you send to us.
  • Billing information: billing name and address. Payment card numbers and bank account details are collected and processed by our third-party payment processor(s) and are not stored by Greypike.
 

2.2 Information Collected Automatically

When you interact with the Services, we and our service providers may automatically collect:

  • Device and connection data: IP address, browser type and version, operating system, device identifiers, and referring or exit URLs.
  • Usage data: pages visited, features used, dates and times of access, and actions taken within the Services.
  • Log data: server logs, error reports, and diagnostic information.
 

2.3 Information From Third Parties

We may receive information about you from:

  • Business partners, resellers, and referral sources;
  • Publicly available databases, including government contracting data sources such as SAM.gov and USASpending.gov;
  • Social media platforms, when you interact with our content or accounts; and
  • Service providers that assist with fraud prevention, analytics, or marketing.
 

2.4 Sensitive Personal Information

We do not knowingly collect “sensitive personal information” as defined under the California Privacy Rights Act (“CPRA”) or comparable state statutes, except to the limited extent that account credentials qualify as such. We do not use sensitive personal information for purposes requiring a consumer’s right to limit under CPRA § 1798.121.

3. Cookies and Similar Technologies

We and our service providers use cookies, pixels, web beacons, local storage, and similar technologies to operate and secure the Services, remember preferences, and analyze traffic.

  • Strictly necessary technologies are required for the Services to function.
  • Analytics technologies help us understand how the Services are used.
  • Marketing technologies, if used, help us measure the performance of advertising.

You can control cookies through your browser settings and, where available, through an in-product cookie preference tool. We honor the Global Privacy Control (“GPC”) browser signal as a valid request to opt out of the sale or sharing of personal information where required by applicable law.

 

4. How We Use Personal Information

We use personal information for the following business purposes:

  • To provide, operate, maintain, and secure the Services;
  • To create and manage accounts and authenticate users;
  • To process transactions and send related confirmations, invoices, and receipts;
  • To respond to inquiries, provide customer support, and communicate with you about the Services;
  • To send administrative communications, including security alerts and changes to terms or policies;
  • To send marketing communications, subject to your right to opt out;
  • To conduct research and analytics to improve the Services;
  • To detect, investigate, and prevent fraud, abuse, unauthorized access, and other unlawful activity;
  • To comply with legal obligations, including those applicable to federal contractors and subcontractors; and
  • To establish, exercise, or defend legal claims.

We will not use personal information for materially different, unrelated, or incompatible purposes without providing notice.

5. How We Disclose Personal Information

We do not sell personal information for monetary consideration. We may disclose personal information in the following circumstances:

  • Service providers and subprocessors: to vendors that perform services on our behalf, including cloud hosting, infrastructure, analytics, email delivery, customer support, payment processing, and security monitoring. These vendors are contractually required to use personal information only to provide services to Greypike and to maintain appropriate confidentiality and security.
  • Affiliates: to our corporate affiliates for purposes consistent with this Policy.
  • Business transfers: in connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, personal information may be transferred as part of the transaction.
  • Legal and safety: when we believe in good faith that disclosure is necessary to (i) comply with applicable law, regulation, subpoena, or other legal process; (ii) protect the rights, property, or safety of Greypike, our clients, our users, or the public; (iii) enforce our agreements; or (iv) investigate and defend against claims.
  • With your direction or consent: at your request or with your consent.

Whether any of the above disclosures constitute “sharing” or a “sale” under state privacy laws depends on context. We do not knowingly share or sell the personal information of consumers under 16 years of age.

6. Data Retention

We retain personal information for as long as reasonably necessary to fulfill the purposes described in this Policy, including to:

  • Provide the Services and maintain your account;
  • Comply with our legal, accounting, tax, and reporting obligations;
  • Resolve disputes and enforce our agreements; and
  • Meet record-retention requirements applicable to federal contractors and their subcontractors, including those arising under the Federal Acquisition Regulation (“FAR”), the Defense Federal Acquisition Regulation Supplement (“DFARS”), and contractually required retention periods.

When personal information is no longer required, we will delete, anonymize, or securely destroy it in accordance with our internal retention schedule.

7. Information Security

We maintain administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, disclosure, alteration, and destruction. These safeguards are commensurate with the sensitivity of the information and the nature of the processing, and include measures such as access controls, authentication requirements, encryption of data in transit, logging and monitoring, and personnel training.

No method of transmission over the Internet or electronic storage is completely secure. We cannot guarantee absolute security, and you use the Services at your own risk. If we become aware of a security incident affecting your personal information, we will notify you and applicable authorities as required by law.

8. Federal Contractor and CUI Considerations

Greypike provides services to organizations in the Defense Industrial Base and other federal contracting environments. When we process information on behalf of such clients:

  • We act as a service provider or subcontractor under the client’s agreement and the applicable federal regulations.
  • Processing of CUI, if any, is governed by DFARS 252.204-7012, NIST SP 800-171, and the client’s contractual instructions;
  • Incident reporting to the client and, where applicable, to the Department of Defense, is performed in accordance with applicable contract clauses; and
  • Where required, services are delivered from environments restricted to U.S. persons and located within the United States.

This Section does not create rights in favor of any person who is not a party to an agreement with Greypike.

]9. Artificial Intelligence and Automated Processing

Certain Services, including GreypikeAI, use artificial intelligence and machine learning technologies. Where we use these technologies:

  • We do not use client CUI or other client-designated confidential information to train generally available third-party foundation models;
  • Inputs and outputs are processed in accordance with the applicable client agreement and, where relevant, federal contract requirements; and
  • We do not make solely automated decisions that produce legal or similarly significant effects concerning you without appropriate human review, except as permitted by law.
 

10. International Data Transfers

Greypike is headquartered in the United States, and the Services are intended for users in the United States. If you access the Services from outside the United States, you understand that your information will be transferred to, stored, and processed in the United States. U.S. data protection laws may differ from those in your jurisdiction. Where required by law, we implement appropriate safeguards for international transfers.

11. Your Privacy Rights

11.1 California Residents (CCPA/CPRA)

If you are a California resident, you have the right to:

  • Know what personal information we collect, use, disclose, and (if applicable) sell or share, including the categories of sources, purposes, and recipients;
  • Access a copy of the specific personal information we have collected about you in the preceding 12 months (or, where applicable, beyond 12 months);
  • Delete personal information we have collected from you, subject to statutory exceptions;
  • Correct inaccurate personal information;
  • Opt out of the sale or sharing of personal information for cross-context behavioral advertising;
  • Limit the use and disclosure of sensitive personal information; and
  • Non-discrimination — we will not deny you services, charge you different prices, or provide a different level of quality because you exercised your rights.

California’s “Shine the Light” law (Cal. Civ. Code § 1798.83) allows California residents to request information about our disclosure of personal information to third parties for their direct marketing purposes. To make such a request, contact us using the information in Section 13.

11.2 Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and Other State Residents

Depending on your state of residence, you may have rights to access, correct, delete, obtain a portable copy of, and opt out of certain processing of your personal information (including targeted advertising, sale, and certain profiling). To exercise these rights, use the methods in Section 12. If we deny your request, you may have the right to appeal our decision by replying to our denial or contacting us as described in Section 13.

11.3 Other Jurisdictions

If you are located outside the United States and applicable law grants you additional rights, we will honor those rights to the extent required.

12. How to Exercise Your Rights

You may submit a rights request using either of the following methods:

Verification. We will take reasonable steps to verify your identity before responding to a rights request, which may include matching information you provide against information we already hold. For sensitive or higher-risk requests, we may require additional verification.

Authorized agents. You may designate an authorized agent to submit a request on your behalf. We may require the agent to provide proof of your written authorization and may require you to verify your identity directly with us.

Response time. We will respond to verifiable requests within the timeframe required by applicable law (generally 45 days, with a permitted extension where needed).

Exceptions. We may decline a request in whole or in part where an exception applies under law, including where the information is necessary to complete a transaction, detect security incidents, protect against fraud or illegal activity, comply with a legal obligation, or exercise another right provided by law.

13. Children’s Privacy

The Services are not directed to children. We do not knowingly collect personal information from children under 13 in violation of the Children’s Online Privacy Protection Act (“COPPA”). If we learn we have collected personal information from a child under 13 without verifiable parental consent, we will delete it.

We also do not knowingly sell or share the personal information of consumers known to be under 16 years of age without opt-in consent as required by CPRA and comparable state laws.

If you believe we may have collected information from a child in violation of this Policy, contact us at [email protected].

14. Email and Marketing Communications

With your permission, where required by law, we may send you marketing communications. You can opt out at any time by following the unsubscribe instructions in the email or by contacting us. We may continue to send you transactional and service-related communications (for example, billing notices and security alerts) regardless of your marketing preferences.

We may use standard email tracking technologies to measure open and click-through rates.

15. Third-Party Links and Services

The Services may contain links to third-party websites and services that we do not operate. This Policy does not apply to those third parties. We encourage you to review the privacy policies of any third-party sites or services you visit.

16. Changes to This Policy

We may update this Policy from time to time. When we make material changes, we will notify you by updating the “Last Updated” date above and, where appropriate, by providing additional notice (such as a banner on the Services or an email to registered users). Your continued use of the Services after an updated Policy takes effect constitutes acceptance of the updated Policy.

17. Contact Us

Greypike, Inc.
42882 Truro Parish Dr, Suite 206
Broadlands, VA 20148

Email: [email protected]
Phone: (703) 214-9246

For the fastest response to a privacy rights request, please use the email address or web form listed in Section 12.


This Policy is intended to describe Greypike’s current practices and does not create a contract or expand any legal rights or obligations beyond those provided by applicable law