Legal
Privacy
A plain-language account of how we handle information. Product security controls are listed on the Security page. Where a signed customer agreement is in place, that agreement governs how deal data is handled.
Scope
This policy covers two things: the public GridLedge website, and the product environment where deal documents are processed. It is written for organizations and individuals in the United States. If your organization has signed a customer agreement with us, that agreement — not this page — governs how your deal data is handled.
Information from the website
The public site may collect standard technical logs such as IP address, browser type, and the pages requested. We use this to operate and improve the site. If you send us a message through the contact section, we receive whatever you choose to include — such as your name, email, and organization — and use it only to reply and follow up.
Information in the product
Inside the product, customers upload construction-period documents for a LIHTC deal — draw packages, change orders, cost workbooks, inspection reports, and related files. Some of these documents may contain personal information about third parties, such as tenant details in a rent roll. That information belongs to the customer and the people it describes; GridLedge processes it on the customer's behalf, under the customer agreement, solely to provide the service. We also hold basic account information for the users who access the product.
How product data is protected
Deal documents and findings are processed in a private Azure environment, isolated by tenant, and encrypted in transit and at rest. They are not used to train shared models. See Security for the controls that are live today.
Sub-processors
We rely on Microsoft Azure for hosting, storage, key management, document extraction (Azure Document Intelligence), and language processing (Azure OpenAI Service). Content processed through Azure OpenAI stays within our Azure environment and is not used to train OpenAI's foundation models. If we add or change a sub-processor that handles personal information, we will update this page.
How we may share information
We share information only where it is needed to run the service: with the sub-processors described above; with other service providers who support our business, under confidentiality obligations; when required by law or in response to a valid legal request; and in connection with a merger, acquisition, or other business transfer, where it stays protected under this policy. We may also share de-identified, aggregated insights as described in the next section. We do not sell personal information, and we do not share it for cross-context behavioral advertising.
De-identified data, benchmarks, and industry insights
We may create de-identified, aggregated data from deal documents and use of the service, and use it for benchmarking, industry statistics, research, service improvement, and insights products shared with participants in the affordable housing industry. Properly de-identified data is not personal information, and we hold it to a public standard: it never includes personal information — tenant information is categorically excluded; we take reasonable measures to ensure it cannot be linked to any deal, property, person, or organization; we maintain and use it only in de-identified form and do not attempt to re-identify it; and anyone who receives it is contractually prohibited from attempting re-identification. Anything we publish or share is aggregated across enough deals and organizations that no single one can be identified. A signed customer agreement may provide additional rights, including opting out of these uses.
Retention
We keep information for as long as needed to provide the service and to meet legal obligations. Deal data is retained and deleted in line with the applicable customer agreement, including on request or at the end of the engagement.
Your choices
You can ask what information we hold about you, request a correction, or request deletion. For information contained in a customer's deal documents, we act on the customer's instructions and will direct your request to them where appropriate. Reach us through the contact details below and we will review each request.
Children
The website and product are intended for business use and are not directed to individuals under 18. We do not knowingly collect information from children.
Changes to this policy
We may update this policy as our practices evolve. When we do, we will post the revised text here with a new effective date.
Contact
Privacy questions can be raised at [email protected], or through the contact section.
Last updated: [effective date]. GridLedge is operated by [legal entity name].