Privacy Policy
Last updated: September 4, 2026
Who this policy covers, and who we are
This policy is issued by Contrayo LLC, a Texas limited liability company ("Contrayo," "we," "us"). It covers two things: this marketing website (contrayo.com), and the Contrayo product itself — the contract lifecycle management software a signed-in organization and its users access. Where something applies to only one of the two, we say so directly.
If your organization is a Contrayo customer, we act as a processor(sometimes called a service provider) with respect to the contract data, counterparty information, and other content your organization submits to the product ("Customer Data") — your organization is the controller of that data, and directs how it's used. We act as a controller of the personal information we collect for our own purposes — account and billing records, security and authentication telemetry (such as the IP address a login attempt comes from and session-token metadata), and our own marketing and waitlist contacts — even where that information relates to a customer's users. This policy covers Customer Data at a high level; ourTerms of Use govern that relationship in more detail. Everywhere else in this policy, we're describing personal information Contrayo itself collects and controls directly — about you as a website visitor, a named product user, or a waitlist signup.
What we collect
From this website. The only information this site collects today is the email address you voluntarily provide on the waitlist / contact form. We don't run analytics, advertising pixels, or tracking cookies of any kind on this site as of this writing — see "Cookies" below.
From the product, once you have an account. If you're a named user of a Contrayo customer's account, we collect: your name, email address, and (optionally) phone number; your password, which we never store or log in plain text — it is stored only as a salted hash produced using a memory-hard hashing algorithm, as described on ourSecurity & Trust page; your display preferences, like timezone, date format, and language; and technical data tied to keeping your account secure, including the IP address a login attempt comes from (used for rate-limiting repeated failed logins) and session-token metadata. Your organization's own name, branding choices, and membership list are also personal information about the people in it, and we hold that the same way.
What we don't separately collect. We don't buy personal information from data brokers, and this site and the product don't run any advertising trackers to build a profile of you across other sites.
SMS and text messaging. If you enable SMS-based multi-factor authentication, we use your mobile phone number solely to send one-time passcodes for account login verification. We do not share your mobile phone number with third parties for their own marketing purposes. Message frequency: you will receive one text message per login or security event requiring verification. Message and data rates may apply. Reply HELP for help, or STOP to opt out at any time.
Why we collect it, and our legal basis for processing it
We use the information above to provide the Service to you and your organization (performing our contract with your organization, or with you directly for the waitlist); to keep accounts and sessions secure (a legitimate interest we and you both share); to communicate with you about the product, including a waitlist signup letting you know when self-serve access opens; and to meet legal obligations that apply to us. Where GDPR applies, one of those is always our basis for a given use — we don't rely on a single blanket justification for everything we do.
AI-assisted processing
Contrayo's product is being built so that any optional AI-assisted feature — for example, suggesting values extracted from a document you upload — runs through a single, controlled integration point, defaults to off for a new organization, and can be disabled entirely by choosing a no-AI mode. As of this writing, no such AI-assisted feature is live in the product. If and when one ships, we'll update this section to say plainly what it does, what data it touches, and how your organization controls it — including whether the underlying model provider is permitted to train on your data (our intent, stated directly: it won't be, without your organization's separate, explicit consent).
Cookies and similar technology
This marketing site sets no cookies at all today. The product sets exactly one: a session cookie, created when you sign in, marked HttpOnly (invisible to page scripts), SameSite=Lax, and Secure over HTTPS — strictly necessary to keep you signed in, not used for tracking or advertising. If that changes — if we ever add analytics or a preference cookie — we'll update this section before we do, not after.
Who we share it with
We don't sell personal information, and we don't share it with third parties for their own marketing purposes. We do share it with a narrow set of infrastructure and service providers who process it on our behalf, under contract, solely to help us run the Service — for example, cloud hosting. We'll disclose personal information if legally required to (a subpoena or court order), to protect Contrayo's or our users' rights and safety, or in connection with a merger, acquisition, or sale of assets, in which case this policy would continue to apply to the transferred information until you're told otherwise.
Where your data is processed, and international transfers
We host the Service on infrastructure located in the United States, and that's true for every customer today regardless of where they or their counterparties are located — see our Security & Trust page for what that hosting actually protects against. For a person in the EEA, UK, or Switzerland whose personal information reaches us this way, we rely on Standard Contractual Clauses or another lawful transfer mechanism, and we'll enter into a Data Processing Addendum addressing GDPR's required terms with any customer that needs one. We're a young company without EU-based infrastructure yet — moving to a second hosting region is a real, planned step if and when our customer base makes it necessary, not something we're claiming exists today.
We do not currently target, market, or offer the Service to individuals in the EEA, the UK, or Switzerland. Where GDPR nonetheless applies to personal information we hold — for example because a customer's own users are located there — we apply the protections described in this policy and will enter into a Data Processing Addendum containing the terms Article 28 requires. If we begin actively offering the Service in those regions, we will appoint a representative under Article 27 and update this policy before we do.
How long we keep it
Waitlist email addresses are kept until you ask us to delete them or until they're no longer needed for the purpose we collected them for, whichever comes first. Account and session data are kept for as long as your account is active, plus a limited period afterward for security and legal purposes — a deactivated account's sessions are revoked immediately, independent of how long the underlying records are retained. Customer Data is retained according to your organization's own agreement with us; when that agreement ends, we make it available for export for 30 days and then delete it, except where we're required to keep it longer by law.
How we protect it
Security specifics — password hashing, session-token handling, tenant isolation, and more — are described in detail, with nothing overstated, on our Security & Trust page, including what we don't have yet (no SOC 2 or ISO 27001 certification, no independent penetration test). That page is the source of truth for security claims; we're not restating every detail here so the two can't drift out of sync with each other.
If we experience a breach of system security involving sensitive personal information, we will notify affected individuals without unreasonable delay and in any event no later than sixty (60) days after we determine a breach occurred. Where the breach affects 250 or more Texas residents, we will also notify the Texas Attorney General as soon as practicable and no later than thirty (30) days after we determine the breach occurred, as Texas Business & Commerce Code § 521.053 requires. Where we hold the affected data as a processor on a customer's behalf, we will notify that customer without undue delay and support its own notification obligations.
Your choices and rights
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal information, and to object to or restrict certain processing. A named product user can update most of their own account information directly from their account settings; for anything else, or if you're a website visitor rather than a product user, contact us using the methods below. We will acknowledge your request promptly and respond within forty-five (45) days, and where a request is complex we may extend that period once by an additional forty-five (45) days, telling you within the first period that we have done so and why. We don't yet have a fully automated self-service request tool for every kind of request — we're small enough today that a real person reads and handles each one directly, which is slower than a big company's automated flow but means an actual person is accountable for getting it right.
California privacy rights
If you're a California resident, the CCPA (as amended by the CPRA) gives you the right to know what personal information we've collected about you, to request its deletion, to correct inaccurate information, and to receive it in a portable format, without discrimination for exercising any of these rights. We don't sell personal information and we don't share it for cross-context behavioral advertising, so there's no "opt out of sale/sharing" toggle to build — there's nothing to opt out of. The categories of personal information described under "What we collect" above are the categories we collect about California residents specifically; we don't collect anything beyond that list for this audience. To exercise any of these rights, contact us using the methods below; we'll verify your identity before acting on the request and respond within the time CCPA requires.
Contrayo does not currently meet the revenue or volume thresholds that make CCPA mandatory for a business. We describe and honor these rights anyway; if that ever changes, the obligations become mandatory and this section will still describe what we do.
Other state and national privacy laws
Several other U.S. states now have their own privacy laws with rights broadly similar to CCPA's, and the EU/UK GDPR gives EEA, UK, and Swiss residents rights along the same lines described above. Rather than maintaining a separate section per jurisdiction, we apply the same practical approach everywhere: tell you plainly what we collect and why, don't sell your data, and respond to a real request from a real person, wherever they are. If a specific jurisdiction's law gives you a right this policy doesn't clearly describe, contact us and we'll work it out directly rather than making you find the right paragraph first.
Texas privacy rights
Contrayo LLC is a Texas company, and the Texas Data Privacy and Security Act (Texas Business & Commerce Code ch. 541) is the privacy law closest to home for us. We describe our practices here and honor the requests below for Texas residents, whether or not a particular Chapter 541 obligation applies to us as a matter of law at any given time. In any event: we do not sell personal data, we do not process personal data for targeted advertising, and we do not sell sensitive data — the one Chapter 541 obligation that applies to a small business regardless of size.
If you are a Texas resident, you may ask us to confirm whether we process your personal data and give you access to it, correct inaccuracies in it, delete it, or provide a portable copy of it. You may also opt out of the sale of personal data, of targeted advertising, and of profiling in furtherance of decisions that produce legal or similarly significant effects concerning you. We do not do any of those three things, so there is nothing to opt out of; if we ever start, we will build the opt-out before we do and describe it here.
How to submit a request, and how to appeal a denial. You can submit a request in either of two ways: by email tolegal@contrayo.com, or through the contact form at contrayo.com. We will respond within forty-five (45) days, with one further forty-five (45) day extension where reasonably necessary and notice to you within the first period. If we decline your request, we will tell you why. You may appeal that decision within a reasonable time by replying to our response or writing tolegal@contrayo.com with "appeal" in the subject line, and we will give you a written decision on the appeal, with our reasons, within sixty (60) days. If we deny the appeal, we will provide you a method to submit a complaint to the Texas Attorney General, which you may also do at any time at texasattorneygeneral.gov.
Sensitive data. We do not ask for, and do not intentionally collect, sensitive data — which under Texas law includes data revealing health diagnosis, sexuality, or citizenship or immigration status; biometric or genetic identifiers; precise geolocation; and personal data collected from a known child. Because customers upload their own contract documents, sensitive data could reach us inside Customer Data. We process Customer Data only as a processor on the customer's documented instructions, and our customer terms ask customers not to upload sensitive personal information unless they have agreed with us in writing that the Service supports it.
Children's privacy
Contrayo is a business product and this site is a business website. Neither is directed at, or intended for use by, anyone under 18, and we don't knowingly collect personal information from a child. If we learn we've collected information from a child, we'll delete it.
Changes to this policy
If this policy changes materially, we'll update the "Last updated" date above and, for changes that affect how we handle a signed-in user's own personal information, tell product users directly rather than relying on them to notice a date change on this page.
Contact us
For any question about this policy, or to exercise a privacy right described above, reach us through the contact form or atlegal@contrayo.com, or write to us at Contrayo LLC, 16307 Lauder Ln, Dallas, TX 75248. We're a small team; a real person will read it.