Effective August 14th, 2025

Overview

Keep Company (“KC”, “we”, “us”, or “our”) is committed to protecting the privacy and security of your personal information. This Privacy Policy describes how we collect, use, disclose, and safeguard your personal information.

This Privacy Policy describes how Keep Company processes personal information, and what choices individuals have with respect to their personal information. By accessing and using a Keep Company product or service, you are agreeing to the practices and policies described in this Privacy Policy. If you object to any practices or policies as described in this Privacy Policy, please do not access or use our services.

We are committed to transparency about our collection, use, transfer and disclosure of your information. Please direct any inquiries, comments or questions regarding this Privacy Policy or our processing of your information to: privacy@keep-company.com.

Scope

This Privacy Policy describes the processing of information provided or collected on the site(s) and/or application(s) where this Privacy Policy is posted. This Privacy Policy applies to all users of all of our services (the “Services”). We follow this Privacy Policy in accordance with applicable law in the places where we operate and process personal information.

The personal information we collect is covered by this Privacy Policy. Please note that our site(s) and/or application(s) may contain links to other sites not owned or controlled by us, and therefore we are not responsible for the privacy practices of those sites. We encourage you to be aware when you leave our sites or applications and to read the Privacy Policy of other sites that may collect your personal information.

Data Controller and Data Processor

Keep Company processes personal information for certain specified purposes, which generally speaking are related to providing our Services and our interests in operating our business.

Depending on the purpose, Keep Company may act as a “data controller” or “business” (in that we collect the personal information and determine the purposes and means of processing personal information), or we may act as a “data processor” or “service provider” (in that we only process personal information on behalf of our customers and per their instructions). For example, when your organization purchases and provides you with access to the Keep Company coaching and mentoring platform, your organization (our customer) is the data controller.

Below you can find more information on the different purposes of processing personal information and Keep Company’s role for each purpose.

Information We Collect

Different business purposes, and different products and services, require processing different categories of personal information. In some cases, the information is collected directly from you or in the background as you use or interact with the product or service (such as, for example, with usage information). In other cases, you may have a choice of whether to provide the personal information to us (such as, for example, with profile information, or with website visitor contact information).

Personal Information

Different business purposes, and different products and services, require processing different categories of personal information. Keep Company adheres to data minimization principles in its processing of personal information.

Generally speaking, we process contact information, company information, client information, app usage information, site usage information, campaign information, and device information, aligned with our stated operational business purposes. In addition, each of our products and services requires different personal information to work as intended.

For example, we may collect and process personal information about you, such as:

  • Name (first name, last name, nickname)

  • Contact information (email address, phone number, mailing address)

  • Company information (company name, industry, size)

  • Job information (job title, seniority level, office location)

  • Demographic information

  • Profile photo 

  • Personal and professional development goals

  • Wellness and behavioral information

  • Attendance and engagement information

Automatically Collected Information

We may collect certain information automatically when we send you an email campaign, such as the email opens, clicks on buttons or links or email bounces.

We may also collect certain information when you visit our website or use our services, such as your IP address, operating system, browser type, and usage data.

For example, when you visit our website or application, we may automatically track the referring and exit URLs, links clicked on, pages viewed, files viewed and downloaded, the amount of time spent on particular pages, the terms used in searches on the website or application and the date and time of a website or app visit.

Information from Other Sources

We may receive personal data about you from other sources to supplement data already collected. For example, as part of your use of the Services, your employer that entered into an agreement to make our Services available may provide us with information about you, such as your contact information. This may also include publicly available data or data provided by third parties. We may combine this data with the data we already have.  We will handle this data in accordance with this Privacy Policy and the purposes outlined when the data was collected. We will notify you if there are any material changes to the way we intend to use this data. Please note that we are not responsible for the accuracy of the data provided by third parties or any consequences arising from the use of such data.

Special Categories of Personal Data

We may process the following special categories of data (also known as sensitive data) as part of our data processing activities:

  • Racial or ethnic origin

  • Health-related data

  • Data concerning a person’s sex life or sexual orientation

When you provide us with these special categories of personal data, we will seek your explicit consent for the processing of such data. This consent will be requested separately and will be clearly presented to you at the point of data collection. You have the right to withdraw your consent at any time by contacting us using the details provided in this Privacy Policy.

How We Use Your Information

We collect information you provide for the following purposes:

  • Service Delivery: We use your personal information to provide you with the products or services you or your organization has requested. This may include creating and maintaining user accounts, providing activity logs, reports, data and analytics features in our platform, making personalized recommendations or resource delivery, sending service messages about the platform such as message notifications, sending gifts to your address, or generally providing access to the features of our platform or services. The lawful basis for this processing is typically the performance of a contract because we need to process your data to fulfill our contractual obligations to you or your organization.

  • Communication: We may use your contact information to communicate with you. This includes sending transactional emails, service updates, and responding to your inquiries or requests. We may also use your contact information for marketing purposes, such as sending newsletters or promotional offers if you have provided your consent or if we have a legitimate interest in doing so. The lawful basis for processing personal information for communication is legitimate interests and, when applicable, consent if you have provided it.

  • Account Management: We use your personal information to manage your account, including account setup, verification, and maintenance. This ensures the security and functionality of your account on our platform. The lawful basis for this processing is typically the performance of a contract to maintain your account.

  • Customer Support: Your information allows us to provide customer support when you have questions or encounter issues with our products or services. This may include troubleshooting, resolving complaints, and addressing your concerns. This processing is based on the legitimate interests to assist you in using our services effectively.

  • Improvement of Services: We analyze your data to analyze, develop, test and improve our Services. This includes running product research and user testing, making data-driven product and business decisions, enhancing the user experience, developing new features, functionality and services, and optimizing the performance and security of our products. This processing is also based on legitimate interests to improve and maintain the quality of our services.

  • Legal Compliance: We may process your personal information to comply with our legal obligations, such as tax reporting, responding to legal requests, or assisting law enforcement agencies when required by law. This processing is necessary to fulfill legal obligations.

  • Contractual Obligations: If you are a client or business partner, we may use your personal information to fulfill our contractual obligations, including managing contracts, invoicing, and providing support as agreed upon in our business relationship. The lawful basis for this processing is the performance of a contract.

  • Fraud Prevention and Security: We use your information to protect against fraud, unauthorized access, and other security risks. This may include monitoring and authenticating account activities and implementing security measures. The lawful basis for this processing is legitimate interests to ensure the security and integrity of our services.

  • Aggregated and Anonymized Data: We may aggregate and anonymize your data to create statistical or research reports, which do not personally identify you. This information may be used for business analysis, marketing, and sharing with partners or clients. The lawful basis for processing aggregated and anonymized data is legitimate interests and the fact that this data is no longer considered personal information.

  • Other Purposes: In addition to the purposes listed above, we may use your personal information for other legitimate purposes, provided that they are compatible with the original reasons for which your data was collected. For these other purposes, we will rely on legitimate interests or other lawful bases as required by applicable laws.

Data Sharing

We disclose information only as it relates to our interests in operating our business and providing our Services, and in accordance with our agreements and legal obligations. More specifically, we disclose information in the following situations, subject to appropriate confidentiality protections.

We may share your personal information with the following categories of recipients:

  • Other Users of our Services: The Keep Company platform is all about human connection, and so by virtue of using our Services some of your information will be disclosed to other users of our Services, including your coach, mentor or fellow group members. For example, when you use the Keep Company platform your “shout-outs” and certain profile information (such as your name and profile picture) will be disclosed to your fellow group members and your coach.

  • Service Providers: We may share your personal information with third-party service providers who assist us in delivering our products and services. These service providers include virtual computing, cloud storage, database management, marketing and customer relationship management, payment processors, tax and accounting services, security monitoring and authentication, product analytics and reporting, customer support and user messaging, legal contracting and consent management services. We will only share the necessary data to fulfill their specific tasks and will have contracts or agreements in place to ensure they process your data securely. The lawful basis for sharing data with service providers is typically the necessity for the performance of a contract or, in some cases, legitimate interests, provided that these interests are not overridden by your data protection rights.

  • Business Partners and Affiliates: In some cases, we may share personal information with our business partners and affiliates, but only when it is necessary for the performance of a contract, the provision of services, or as part of a legitimate business interest. For example, we may share data with a partner organization involved in co-branded events or services. Sharing data with business partners and affiliates may be necessary for the performance of a contract or based on legitimate interests, especially when these partnerships are essential for delivering integrated or co-branded services.

  • Legal Authorities: We may be required to share personal information with legal authorities, regulatory bodies, or law enforcement agencies when necessary to comply with legal obligations or respond to valid requests for information, as permitted by the law. The lawful basis for sharing with legal authorities is the necessity to comply with a legal obligation.

  • Merger or Acquisition: In the event of a merger, acquisition, or sale of all or part of our business, the sharing of personal information with the acquiring entity or parties involved in the transaction may be based on legitimate interests, as it's necessary for the legitimate interests pursued by us or the acquiring entity. We will ensure that your data remains protected and used in accordance with this Privacy Policy.

  • Publicly Available Information: We may share personal information that is publicly available, such as information from public records or online sources. However, we will do so only when it is relevant to the purposes for which your data was collected and used. Sharing publicly available personal information is typically based on legitimate interests, as it is in the legitimate interests of our business to use publicly available data for relevant purposes.

  • With Your Consent: We may share your personal information with third parties if you have provided your explicit consent for such sharing. We will always request your consent before sharing your data for specific purposes. If you have provided explicit consent for sharing your personal information with specific third parties, the lawful basis for sharing is your consent.

  • Other Legitimate Business Interests: In certain cases, we may share personal information with other parties for legitimate business interests. The sharing of this personal information may be based on legitimate interests. We will always ensure that such sharing is conducted in accordance with applicable data protection laws and respect your rights.

Data Transfers

Our Services are designed and delivered primarily in the United States with a global workforce. As such, we may need to transfer your information to countries other than the one in which you live. We take reasonable steps to protect your information in accordance with this Privacy Policy and applicable laws.

As a global organization, we may transfer your personal data to countries outside the European Union (EU) or the European Economic Area (EEA). Such transfers may be necessary for the purposes outlined in this Privacy Policy, including providing you with requested products or services, communicating with you, and conducting our business operations effectively.

When we transfer your personal data to countries outside the EU/EEA, we will ensure adequate safeguards are in place to protect your personal data as required by applicable data protection laws and regulations. These safeguards may include (but are not limited to):

  • Standard Contractual Clauses: We may use standard contractual clauses approved by the European Commission or other relevant data protection authorities to ensure the protection of your personal data during transfer.

  • Binding Corporate Rules (BCRs): Where applicable, we may rely on BCRs adopted by our organization to ensure the protection of personal data transferred across borders within our corporate group.

  • Data Protection Agreements: We may enter into agreements with recipients of your personal data outside the EU/EEA, imposing obligations on them to protect your personal data to the same standards required in the EU/EEA.

  • Certification Mechanisms: We may rely on certification mechanisms such as the EU-U.S. Privacy Shield Framework (https://www.dataprivacyframework.gov/), where applicable, to ensure that third-party recipients of your personal data provide an adequate level of protection.

By using our services or providing your personal data to us, you consent to the transfer of your personal data as described in this Privacy Policy. If you do not agree to such transfers, please refrain from using our services or providing your personal data to us.

If you have any questions or concerns regarding the transfer of your personal data outside of the EU/EEA or the safeguards we have implemented, please contact us using the contact details provided at the end of this Privacy Policy.

Data Subject Rights

You have certain rights with respect to your information as further described in this section. Your local laws (including applicable laws in the EU, UK, Switzerland,California, Connecticut, and Colorado, as well as similar U.S. state laws) may require us to comply with the following individual rights:

Right to Access

You may have the right to request access to your personal data that we process. This means you may ask us to provide you with information about what personal data we hold about you and how we use it. 

Right to Rectification

You may have the right to request the correction or updating of your personal data if it is inaccurate or incomplete. If so, we will make the necessary changes and inform any third parties to whom we have disclosed the data. 

Right to Erasure (Right to Be Forgotten)

You may have the right to request the deletion of your personal data under certain circumstances. This right is not absolute and can be exercised if the data is no longer necessary, you withdraw consent, or the data processing is unlawful. 

Right to Restriction of Processing

You may have the right to request the restriction of the processing of your personal data under specific circumstances. This means we will limit the way we use your data but not delete it entirely. This right might be exercised when you contest the accuracy of the data, the processing is unlawful, or you need the data for legal claims. 

Right to Data Portability

You may have the right to request a copy of your personal data in a structured, commonly used, machine-readable format, or you can ask us to transmit it directly to another data controller where technically feasible. This right is applicable when processing is based on consent or the performance of a contract. 

Right to Object

You may have the right to object to the processing of your personal data, including processing based on legitimate interests or for direct marketing purposes. If so, we will stop processing your data for such purposes unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms. 

Automated Decision-Making and Profiling

You may have the right not to be subject to a decision based solely on automated processing, including profiling, which has legal or significant effects on you. You may have the right to request human intervention in the decision-making process. If so, we will inform you when such decisions are made, provide you with the opportunity to express your point of view, and ensure there are human interventions available. 

Withdraw Consent

If we process your personal data based on your consent, you may have the right to withdraw that consent at any time. This will not affect the lawfulness of processing based on consent before its withdrawal. 

If you wish to exercise your data subject rights, please contact us at privacy@keep-company.com. We will consider all requests and provide our response within the time period stated by applicable law and as otherwise required by applicable law. Please note, however, that certain information may be exempt from such requests in some circumstances, which may include if we need to keep processing your information for our legitimate interests or to comply with a legal obligation.

We may request you provide us with information necessary to confirm your identity before responding to your request. We cannot respond to your request or provide you with the information you seek if we cannot verify your identity or authority to make the request and confirm the request relates to you and your information. Depending on applicable law, you may have the right to appeal our decision to deny your request. If we deny your request, we will provide you with information on how to appeal the decision, if applicable, in our communications with you.

Data Security

We implement and maintain reasonable and appropriate technical and electronic safeguards to protect the security of your personal information from loss, misuse, unauthorized access, disclosure, alteration, or destruction. 

While we implement these security measures to protect your data, it is important to understand that no online platform can guarantee absolute security. Therefore, we encourage you to take necessary, best-practice precautions to maintain the security of your password or other forms of authentication involved in accessing password-protected or secured resources, such as strong, unique passwords and being cautious with the sharing of login credentials.

In the event of a data breach or security incident, we will take immediate action to isolate and resolve the incident based on our incident response resolution procedures, notify relevant authorities, and inform affected data subjects in compliance with applicable data protection laws. 

Data Retention and Disposal

We will only retain your personal data for as long as necessary to fulfill the purposes we collected it for, including for the purposes of satisfying any legal or contractual requirements.

To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorized use or disclosure of your personal data, the purposes for which we process your personal data, and whether we can achieve those purposes through other means, as well as applicable legal requirements.

Upon expiration of the applicable retention period, we will securely delete or anonymize your personal data in accordance with applicable laws and regulations.

Cookies and Tracking Technology

We may use “cookies” (or similar tracking technology) on our website. Cookies are text files that our web server may play on your hard disk to store your preferences. When you visit our website, you will be presented with a cookie banner or pop-up requesting your consent to use non-essential cookies. You have the right to accept or decline the use of such cookies. Your consent can be managed and changed at any time through your device or browser settings. 

Cookies, by themselves, do not provide us with any PII unless you explicitly choose and consent to provide this information to us. Once you choose and consent to provide PII, however, this information may be linked to the data stored in the cookie. If you choose to turn off collection of cookies through your device or browser, certain features of our service may not function properly without the aid of cookies.

Our website may also incorporate third-party cookies and tracking technologies. These technologies are subject to the privacy policies and practices of the respective third parties. We encourage you to review the privacy policies of these third parties for information on how they collect and use your personal data.

Children

We do not knowingly collect any information from minors. In situations where personal data from anyone under the age of 16 is needed for data processing activities, we will obtain authorization from an appropriate parent or guardian. If such authorization is unable to be obtained, data processing activities for that data subject will be terminated. In the event that we discover that a minor under the age of 16 has provided PII to us, we will make efforts to delete the information ASAP. If you have concerns about our website or service offering, wish to find out if your child has accessed our services, or wish to remove your child’s personal data from our servers, please contact us at privacy@keep-company.com. 

European Data Protection Rights

If the processing of personal data about you is subject to European Union (EU) data protection law, you have certain rights with respect to that data. Please refer to section “Data Subject Rights” above for a listing of these rights. 

Additionally, our processing of your personal data is based on specific legal bases as defined in EU data protection law. Please refer to section “Data Sharing” above for a listing of these legal bases.

Location of Personal Information

Our service is hosted in the United States and all personal information collected with the service is stored in the United States, while some information may temporarily be stored on servers in other countries for the purposes of performance and security. If you are visiting our site or using our service, please be aware that you are transferring personal data to the United States.

Updates to this Privacy Policy

We periodically review this Privacy Policy and may make updates to reflect changes in our practices, for legal reasons, or to meet new regulatory requirements. Your continued use of our services following any notice of changes to this Privacy Policy means you accept such changes. Please refer to the “Effective Date” above for details on when this Privacy Policy was last updated.

Contact Us

If you have any questions, concerns, or requests regarding your personal data or this Privacy Policy, please contact us at privacy@keep-company.com. For specific requests relating to your rights as a data subject including the rights noted in section “Data Subject Rights” noted above, please contact our Data Protection Officer (DPO) directly at privacy@keep-company.com. If you are in the EU, please contact our EU Privacy Representative directly at https://keepcompany.gdprlocal.com/eu 


Keep me in the Loop

Contact

hello@keep-company.com

(301) 304-1084

7411 Arlington Rd
Bethesda, MD 20814

Keep me in the Loop

Contact

hello@keep-company.com

(301) 304-1084

7411 Arlington Rd
Bethesda, MD 20814

Keep me in the Loop

Contact

hello@keep-company.com

(301) 304-1084

7411 Arlington Rd
Bethesda, MD 20814