Privacy Policy

Last Updated: Jan 15, 2026

1. Introduction

Obsidion.ai ("Obsidion," "we," "our," and/or "us") values the privacy of individuals who use our website (https://www.obsidion.ai/) and any of our other websites, applications, or AI-powered services that link to this Privacy Policy (collectively, our "Services").

This Privacy Policy (the "Privacy Policy") explains how we collect, use, process, and disclose personal data from users of our Services. By using our Services, you agree to the collection, use, processing, and disclosure of your personal data as described in this Privacy Policy. Beyond this Privacy Policy, your use of our Services is also subject to our Terms of Service.

Definitions:

  • Business Customer: A business, contractor, or service provider who subscribes to our Services to manage their own client relationships and operations.
  • End User: An individual client or customer of a Business Customer who interacts with our platform through the Business Customer's website or services.

2. Information We Collect

We collect only the personal data that is necessary and proportionate to provide you with our Services and to maintain the security and performance of our platform.

A. Information You Provide to Us

  • Business Account Information: If you are a Business Customer, we collect information necessary to manage your account, such as your name, business name, professional email address, mailing address, and phone number.
  • Customer Lead Data: When you use our Services to manage your own clients, we collect the personal data you or your clients provide through our integrated tools. This may include names, contact details, and service requests.
  • Communications: If you contact us directly for a demo, support, or via our contact forms, we receive additional personal data such as your name, email address, and the contents of your message.
  • Careers: If you apply for a position at Obsidion.ai, we collect your contact information and any personal data included in your resume or cover letter.

B. Information We Collect When You Use Our Services

  • Device Information: We receive information about the device and software you use to access Obsidion.ai, including internet protocol (IP) address, web browser type, and operating system version.
  • Usage Information: We automatically receive information about your interactions with our platform, such as the length of time spent on pages, objects or links clicked, and the dates and times of your visits.
  • Cookies and Similar Technologies: We and our third-party partners use cookies, pixel tags, and similar technologies to understand usage patterns and improve our platform.

Types of Cookies We Use:

  • Essential Cookies: Required for basic platform functionality (e.g., session management, security)
  • Analytics Cookies: Help us understand how visitors interact with our Services (e.g., Google Analytics)
  • Functional Cookies: Remember your preferences and settings
  • Marketing Cookies: Used to deliver relevant advertisements and track campaign effectiveness

You can modify your cookie settings through your browser preferences. Disabling certain cookies may limit some features of our Services.

C. Personal Data We Receive from Third Parties

  • Integration Partners: We may receive information from third-party services you integrate with our platform (such as GoHighLevel, Vercel, or social media platforms used for lead generation) to facilitate the delivery of our Services.
  • Marketing Partners: We may receive personal data from marketing partners to help us reach potential Business Customers who may be interested in our AI-integrated web solutions.

D. Payment Processing

When you purchase a subscription or service through Obsidion.ai, your payment is processed by our third-party payment processor, Stripe. Stripe collects your name, billing address, and financial information ("Payment Information"). The use of your data by Stripe is governed by their Privacy Policy. Obsidion.ai does not store or process your full credit card information.

E. Sensitive Data

Obsidion.ai does not intentionally collect "Sensitive Data" (such as social security numbers, government-issued identification numbers, health information, or biometric data) as defined by applicable privacy laws. However, Business Customers may use our platform to collect such data from their own End Users (e.g., dietary restrictions or accessibility needs). In such cases, the Business Customer acts as the data controller and is responsible for obtaining necessary consent and complying with applicable laws. Obsidion.ai processes this data solely as a service provider on behalf of the Business Customer.

3. Legal Basis for Processing (GDPR)

For users in the European Economic Area (EEA), United Kingdom, or Switzerland, we process your personal data under the following legal bases:

  • Performance of Contract: To provide our Services as outlined in our Terms of Service
  • Legitimate Interests: To improve our platform, prevent fraud, and ensure security
  • Consent: For marketing communications and certain cookie usage (where required)
  • Legal Obligation: To comply with applicable laws and regulations

You have the right to withdraw consent at any time where we rely on consent as the legal basis for processing.

4. How We Use Your Information

We use the personal data we collect for various business and operational purposes, depending on your relationship with us and the specific Services you use. We use your information to:

  • Provide and Maintain Our Services: To operate the Obsidion.ai platform, manage your business account, facilitate the hosting of your website, and ensure platform integrations function correctly.
  • Improve and Enhance the Platform: To understand and analyze how you and your End Users interact with our Services. This allows us to debug issues, develop new features, and optimize the user interface and experience.
  • Communicate with You: To send you technical notices, updates, security alerts, and administrative messages. We also use your contact information to respond to your comments, questions, and support requests.
  • Facilitate Payments: To process your subscription fees and transactions through our third-party processor, Stripe.
  • Marketing and Promotions: To send you promotional communications about new features, products, or services offered by Obsidion.ai that may be of interest to you. You may opt-out of these communications at any time by clicking the "unsubscribe" link at the bottom of any marketing email or by contacting us at support@obsidion.ai.
  • Compliance and Legal Obligations: To enforce our Terms of Service, comply with applicable laws, and respond to lawful requests from public and government authorities.
  • Fraud Prevention and Security: To detect, investigate, and prevent fraudulent transactions, unauthorized access to the platform, and other illegal activities.
  • Aggregate Data Analysis: To create anonymized, internal-only reports on usage trends that do not identify individuals, which helps us scale our infrastructure and service offerings.

5. How We Share Your Information

Obsidion.ai does not sell, rent, or lease your personal data to third parties. We only share your information in the following limited circumstances:

A. Service Providers and Sub-Processors

We share information with trusted third-party vendors who perform services on our behalf. These service providers assist us with:

  • Cloud infrastructure and website hosting
  • Customer relationship management (CRM) tools and dashboards
  • Payment processing
  • Analytics and platform performance monitoring
  • Email and SMS communication delivery
  • Customer support and ticketing systems

All service providers are contractually obligated to keep your information confidential and are prohibited from using your personal data for any purpose other than providing services to Obsidion.ai.

B. Business Transfers

In the event that Obsidion.ai is involved in a merger, acquisition, financing, or sale of assets, your information may be transferred as part of that business transaction. We will notify you via email and/or a prominent notice on our website at least 30 days before any such change in ownership or control of your personal data.

C. Compliance with Law

We may disclose your information if we believe in good faith that such disclosure is necessary to comply with a legal obligation, protect our rights or property, or ensure the safety of our users and the public.

D. With Your Consent

We may share your information with third parties in other circumstances specifically described to you at the time of collection, provided we have obtained your explicit consent.

6. SMS and Mobile Messaging

Obsidion.ai provides a platform that allows our Business Customers to communicate with their End Users via SMS and mobile messaging.

A. Consent and Opt-In

By providing your phone number through a web form, signup page, or other opt-in mechanism, you explicitly consent to receive automated text messages (e.g., appointment reminders, service updates, and marketing messages) from us or on behalf of our Business Customers. Consent to receive marketing text messages is not a condition of purchase.

B. Opt-Out and Help

  • Unsubscribe: You can cancel the SMS service at any time by texting "STOP" to the number from which you received the message. After you send "STOP," we will send you a confirmation message that you have been unsubscribed. You will no longer receive SMS messages from that specific sender.
  • Support: If you are experiencing issues with the messaging program, you can reply with "HELP" for assistance, or contact us directly at support@obsidion.ai.

C. Carrier Information

Message and data rates may apply for any messages sent to you from us and to us from you. Message frequency varies based on your interaction with the platform. Carriers are not liable for delayed or undelivered messages.

D. No Third-Party Marketing Sharing

No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties. We do not sell, rent, or lease our registered text messaging lists.

7. Third-Party Services

Our Services may contain links to or integrations with other websites or services that we do not own or operate. We are not responsible for the privacy practices of these third parties. This Privacy Policy does not apply to your activities on third-party services. We encourage you to read their privacy policies before providing any personal data to them.

8. Data Retention and Deletion

We retain your personal data only for as long as necessary to fulfill the purposes described in this Privacy Policy:

  • Account Data: Retained for the life of your account plus 90 days after account closure to provide our Services and handle any disputes
  • Transaction Records: Retained for seven (7) years to meet tax, legal, and regulatory requirements
  • Communication Logs: Generally retained for up to two (2) years for quality assurance and support optimization
  • Marketing Data: Retained until you opt-out or request deletion

Deletion Requests

You may request account deletion by emailing support@obsidion.ai. We will fulfill deletion requests within 30 days, except where retention is required by law, for fraud prevention, or to resolve disputes. Upon deletion, we will either delete or anonymize your personal data.

9. Security

We protect your personal data through technical, physical, and administrative safeguards, including:

  • Encryption: Data is encrypted both in transit (SSL/TLS) and at rest using industry-standard encryption protocols
  • Access Control: Strict role-based access ensures only authorized personnel can interact with specific data segments
  • Monitoring: Continuous security monitoring for unauthorized access or anomalies
  • Regular Audits: Periodic security assessments and updates to our infrastructure

While we implement robust security measures to safeguard your data, no electronic storage system or transmission method is 100% secure. Therefore, we cannot guarantee absolute security.

10. International Data Transfers

Our Services are hosted in the United States. If you access Obsidion.ai from the European Economic Area (EEA), United Kingdom, Switzerland, or other regions with data protection laws, please note that your personal data will be transferred to, stored, and processed in the United States.

For EEA, UK, and Swiss users, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission to ensure adequate protection of your personal data during such transfers. By using our Services, you acknowledge and consent to this transfer and processing.

11. Children's Privacy

Obsidion.ai does not knowingly collect or maintain personal data from children under the age of 13 (or 16 in the EEA). Our Services are strictly intended for business use and are not directed to children. If we learn that a child has provided us with personal data without parental consent, we will delete it immediately. If you believe we may have collected information from a child, please contact us at support@obsidion.ai.

12. Your Privacy Rights

Your privacy rights depend on your location. We are committed to honoring all applicable privacy rights regardless of where you reside.

A. California Residents (CCPA/CPRA)

If you are a California resident, you have the following rights:

  • Right to Know/Access: Confirm whether we process your personal data and receive a copy of the data we hold about you
  • Right to Delete: Request the permanent removal of your personal data
  • Right to Correct: Request correction of inaccurate or incomplete information
  • Right to Opt-Out: Opt-out of the "sale" or "sharing" of personal data for targeted advertising (Note: Obsidion.ai does not sell your personal data)
  • Right to Limit Use of Sensitive Personal Information: Request limits on our use of sensitive personal information
  • Right to Non-Discrimination: You will not receive discriminatory treatment for exercising your privacy rights

We will respond to verified requests within 45 days, which may be extended by an additional 45 days if necessary.

B. Other U.S. State Residents

If you are a resident of Virginia, Colorado, Connecticut, Utah, or other states with comprehensive privacy laws, you may have similar rights to those described above for California residents. Specific rights and procedures may vary by state.

C. EEA, UK, and Swiss Residents (GDPR)

If you are located in the EEA, UK, or Switzerland, you have the following rights:

  • Right of Access: Obtain confirmation of whether we process your personal data and access to that data
  • Right to Rectification: Correct inaccurate or incomplete personal data
  • Right to Erasure: Request deletion of your personal data under certain circumstances
  • Right to Restriction of Processing: Request that we limit how we use your personal data
  • Right to Data Portability: Receive your personal data in a structured, commonly used, machine-readable format
  • Right to Object: Object to our processing of your personal data for certain purposes
  • Right to Withdraw Consent: Withdraw consent at any time where we rely on consent as the legal basis
  • Right to Lodge a Complaint: File a complaint with your local data protection authority

We will respond to requests within 30 days.

D. How to Exercise Your Rights

To exercise any of these rights, please contact us at:

We may require verification of your identity before processing your request to protect your privacy and security.

13. European Representative and Data Protection Officer

For users in the EEA or UK, if you have questions about our data practices or wish to exercise your rights, you may contact:

14. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will post the updated Privacy Policy on this page and update the "Last Updated" date below.

If we make material changes to how we handle personal data previously collected, we will notify you via:

  • A prominent notice on our platform, and/or
  • Email to your registered email address

Your continued use of our Services after such changes constitutes acceptance of the updated Privacy Policy.

15. Contact Us

If you have questions regarding this Privacy Policy or our data practices, please contact us at:

Obsidion.ai

Email: support@obsidion.ai

Privacy Email: privacy@obsidion.ai

Last Updated: Jan 15, 2026