![masthead background decorative image](/images/legal-bg.avif)

# _Privacy_ Policy

Last updated

July 30, 2026

Monitoring the Situation, Inc. d/b/a Clusia ("Clusia," "we," "us") provides compliance services and software to financial institutions, fintechs, and their partners. This Privacy Policy explains how we handle personal information.

The most important thing to understand about how we work: most of the information we hold belongs to our business customers, not to us. When a customer connects a system or uploads a document, we process what's in it on that customer's behalf and under their instructions. This policy covers both that processing and the information we collect for ourselves.

## _01._ Two Kinds of Information

**1.1 Customer Data** – processed on our customers' behalf. When a business customer uses Clusia, we receive information from their systems, documents, and personnel in order to prepare and deliver their compliance work. This may include names, work contact details, roles, and – depending on what their systems contain – records relating to their own customers, transactions, complaints, or account activity.

For this information, our customer is the controller and Clusia is the processor (or "service provider"). We process it only to perform the services, as described in our agreement with that customer and the applicable Data Processing Addendum. If you are an individual whose information appears in a customer's data and you want it corrected or deleted, contact that business directly – we will support them in responding.

**1.2 Information we collect for ourselves.** We are the controller of information about the people who visit our website, contact us, and use our platform in a work capacity – account details, communications, and usage data. This policy governs that information.

## _02._ Information We Collect

Account and profile. Name, work email, employer, job title, credentials (for example an AAP accreditation), and authentication data.

**Engagement participation.** Records of actions taken in the platform – answers confirmed, evidence attached, comments and notes written, requests sent and answered, sections completed, reviews performed, and signatures applied – together with the name, timestamp, and account of the person who took each action. These records are part of the audit trail and cannot be edited or deleted. See Section 7.

**Signature information.** When you sign a statement of completion or attestation, we record your typed name, account identity, organization, credential, timestamp, IP address, and device information as evidence of the signature.

**Connected systems.** With a customer's authorization, we access their systems on a read-only basis. We never write to a connected system. Credentials are held by the customer's identity provider or the connected service; we store access tokens, not passwords.

**Uploaded content.** Policies, agreements, procedures, reports, exports, and other files a customer or a participant uploads.

**Website and usage.** IP address, browser and device information, pages viewed, referring source, and information from cookies and similar technologies. See Section 9.

**Communications.** Messages you send us, support requests, sales inquiries, and – where you are notified in advance – call recordings or transcripts.

We do not intentionally collect biometric data, government identification numbers, health information, or precise geolocation, and we ask customers not to upload them unless an engagement genuinely requires it.

## _03._ How We Use Information

-   To deliver engagements – preparing, drafting, reviewing, and issuing compliance deliverables
-   To operate, secure, and support the platform
-   To authenticate users and administer permissions, including limited-scope external participants
-   To maintain the audit trail and produce records required for regulatory retention
-   To communicate about engagements, deadlines, and service changes
-   To meet our own legal, tax, and regulatory obligations
-   For product improvement, subject to Section 5
-   With consent, for marketing – which you can withdraw at any time

We do not sell personal information, and we do not share it for cross-context behavioral advertising.

## _04._ Automated Processing

Our platform uses automated and machine-learning techniques to locate relevant information, draft responses, and assemble supporting evidence.

These systems propose; people decide. No drafted content becomes part of a signed deliverable without human review, and professional judgments – findings, sufficiency of evidence, whether to sign – are made by accredited practitioners. We do not use automated processing to make decisions producing legal or similarly significant effects about individuals.

## _05._ Model Training

We do not use customer content to train models that serve other customers. Improvements derived from one customer's engagements are not applied to another customer's data without that customer's written consent.

## _06._ When We Share Information

Our customer's own organization. People a customer authorizes – including external participants invited to answer specific questions – see what that customer has granted them access to.

**Reviewers and partner firms.** Accredited practitioners, including those at partner firms we engage to review and sign work, access engagement information as necessary to perform the review. They are bound by confidentiality and professional obligations.

**Recipients our customers designate.** At a customer's direction, completed deliverables may be provided to their sponsor bank, examiner, or counterparties.

**Service providers.** Cloud hosting, model providers, email and communications, analytics, payment processing, and support tooling – each bound by contract to process information only on our instructions. Our current subprocessors are listed at trust.clusia.com.

**Legal and regulatory.** We may disclose information to comply with law, respond to lawful requests from regulators, networks, or law enforcement, enforce our agreements, or protect rights and safety. Where we are legally permitted, we will notify the affected customer first.

Corporate transactions. In connection with a merger, acquisition, financing, or sale of assets, subject to this policy continuing to apply.

## _07._ Retention

Engagement records and deliverables. Compliance work is subject to recordkeeping rules. Signed deliverables, the supporting engagement record, and the audit trail are retained for six (6) years after completion – or longer where law requires – even if the customer closes their account. This retention is a legal requirement of the work itself and is not subject to deletion on request.

**Audit trail immutability.** Entries in the audit trail – who did what, and when – cannot be edited or deleted by any user, including us. Corrections are recorded as new entries.

**Connected-system data.** Data drawn from connected systems is retained only as long as needed to complete and support the engagement, then deleted or archived within the engagement record.

**Account and marketing data.** Retained while the account is active and for 24 months afterward, unless a longer period is required.

## _08._ Your Rights

Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal information; to object to or restrict processing; to withdraw consent; and to appeal a refusal. We will not discriminate against you for exercising these rights.

To exercise a right, contact privacy@clusia.com. We will verify your identity before responding and will respond within the period required by law.

If your information is in a customer's data, direct your request to that business. We will assist them in fulfilling it – subject always to the retention requirements in Section 7.

California. We do not sell or share personal information as those terms are defined under the CCPA/CPRA. The categories we collect, our purposes, and our disclosures are described above.

EEA/UK. Where applicable, our legal bases are performance of a contract, legitimate interests (operating and securing the services), consent (marketing and cookies), and legal obligation. International transfers are made under Standard Contractual Clauses or another approved mechanism.

## _09._ Security

We maintain administrative, technical, and physical safeguards designed to protect information, including encryption in transit and at rest, tenant isolation, least-privilege access, logging of access and system activity, and vendor security review. Details are published at trust.clusia.com.

No system is perfectly secure. If we become aware of a breach affecting personal information, we will notify affected customers and individuals as required by law and by our agreements.

## _10._ Children

The services are for business use. We do not knowingly collect information from anyone under 18. If we learn we have, we will delete it.

## _11._ Changes

We will post updates here and revise the "Last updated" date. For material changes, we will provide notice – by email or in the platform – before they take effect.

## _12._ Contact

Clusia (Monitoring the Situation, Inc.): privacy@clusia.com

Overview

-   01\. Two Kinds of Information
-   02\. Information We Collect
-   03\. How We Use Information
-   04\. Automated Processing
-   05\. Model Training
-   06\. When We Share Information
-   07\. Retention
-   08\. Your Rights
-   09\. Security
-   10\. Children
-   11\. Changes
-   12\. Contact