Legal
Privacy Policy
Effective date
This Privacy Policy explains how CivAura handles information in connection with the CivAura platform and the CivAura Grant Assistant browser extension.
CivAura (“CivAura,” “we,” “us,” or “our”) provides software and related services to help authorized users manage and complete grant workflows. This Privacy Policy explains how we collect, use, disclose, and protect information when you use the CivAura website, platform, and the CivAura Grant Assistant browser extension (collectively, the “Services”).
By using the Services, you agree to this Privacy Policy.
1. Scope
This Privacy Policy applies to information processed through:
- the CivAura website and platform;
- the CivAura Grant Assistant browser extension; and
- related support, communications, and service operations.
The CivAura Grant Assistant extension is a companion tool for CivAura users and is not intended to be used as a standalone product.
2. Information We Collect
We may collect and process the following categories of information.
A. Account and Organization Information
When you use CivAura, we may process information such as:
- name
- email address
- organization name
- role or account type
- account identifiers
- contact information associated with your organization or workspace
B. Workspace and Grant Workflow Information
To provide the Services, we may process information stored in or submitted to your CivAura workspace, including:
- grant application and reporting information
- project details
- organization details
- contact names, titles, phone numbers, and email addresses
- addresses and location-related mailing information
- budget and funding-related application data
- other information you choose to store in CivAura for workflow completion
This information may include personally identifiable information where relevant to your grant workflow.
C. Website and Portal Content
When you use the browser extension on an external portal, the extension may access and process relevant page content needed to perform the requested workflow, such as:
- field labels
- form structure
- dropdown options
- user-selected fields
- page text needed to identify where information should be entered
We use this information only to support the extension’s functionality and related service operations.
D. Authentication and Session Information
We may process information needed to determine whether you are signed in and authorized to use the Services, such as:
- session status
- authentication state
- account access state
- browser/session information necessary to securely connect the extension to your CivAura account
We do not describe this as collecting passwords through the extension itself unless explicitly provided through CivAura’s own sign-in flow.
E. Technical and Usage Information
We may collect technical and operational data such as:
- browser type
- device and extension environment information
- service logs
- error and diagnostic data
- feature usage and activity records needed for security, reliability, support, and product improvement
- usage and limits/accounting information related to service operations
3. How We Use Information
We use information to:
- provide, maintain, and improve the Services;
- authenticate users and enforce account, organization, and project access controls;
- populate and assist with grant workflows in external portals when requested by the user;
- generate, structure, map, and return workflow-related outputs requested by the user;
- support reporting, troubleshooting, debugging, and customer support;
- monitor usage, enforce applicable limits, and protect the Services from misuse or abuse;
- comply with legal obligations; and
- protect the security, integrity, and availability of the Services.
4. How the Browser Extension Works
The CivAura Grant Assistant extension is designed for authenticated CivAura users. When a signed-in user invokes the extension on a portal page, the extension may:
- communicate with the CivAura backend;
- access relevant portal page content needed to identify and complete workflow fields;
- retrieve authorized workspace information from CivAura;
- help complete requested workflow actions in external portals.
The extension is intended to function only for authorized users with access to CivAura.
5. Legal Bases / Authorized Use
Where applicable, we process information because:
- it is necessary to provide the Services requested by the user or organization;
- it is necessary for our legitimate interests in operating, securing, and improving the Services;
- it is necessary to comply with legal obligations; or
- we otherwise have permission or authorization to do so.
6. Sharing of Information
We do not sell personal information.
We may share information only in the following limited circumstances:
- with service providers and infrastructure providers that help us operate the Services;
- with vendors that process data on our behalf for hosting, security, analytics, authentication, support, or related technical operations;
- when necessary to respond to lawful requests, comply with law, or protect rights, property, or safety;
- in connection with a merger, acquisition, financing, restructuring, or sale of assets; or
- with your direction or consent.
We do not use or transfer user data for purposes unrelated to the Services’ single purpose, and we do not use or transfer user data to determine creditworthiness or for lending purposes.
7. Cookies, Storage, and Local Device Data
We may use cookies, browser storage, and similar technologies to:
- keep users signed in;
- remember extension state or configuration;
- support secure communication between the extension and CivAura;
- improve performance and reliability;
- support product functionality and security.
In the extension, limited local storage may be used for extension state and configuration. We do not use local storage as a substitute for authorization checks.
8. Third-Party Sites and Portals
The Services may interact with third-party sites, grant portals, or external systems at the direction of the user. We are not responsible for the privacy practices of third-party sites or services. Their privacy policies and terms may also apply.
9. Data Retention
We retain information for as long as reasonably necessary to:
- provide the Services;
- maintain account and workspace functionality;
- comply with legal obligations;
- resolve disputes;
- enforce our agreements; and
- protect the Services.
Retention periods may vary depending on the type of information and the context in which it was collected.
10. Security
We use reasonable administrative, technical, and organizational safeguards designed to protect information. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
11. User Choices and Access
Depending on your relationship with CivAura and applicable law, you may be able to:
- access, update, or correct certain account information;
- request deletion of certain information;
- request information about how your data is used; or
- close your account, subject to legal and contractual requirements.
If you use CivAura through an organization, some requests may need to be handled through your organization administrator.
12. Children’s Privacy
The Services are not directed to children under 13, and we do not knowingly collect personal information from children under 13 through the Services.
13. International Data Transfers
If you access the Services from outside the country where our systems are located, your information may be transferred to and processed in other jurisdictions where privacy laws may differ.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we do, we will update the Effective Date above. Your continued use of the Services after changes become effective constitutes acceptance of the updated Privacy Policy.
15. Contact Us
If you have questions about this Privacy Policy, you can contact us at:
Email: contact@civaura.com