Solutions Pricing About Contact

Legal

Privacy Policy

How Drytis collects, uses, discloses, and protects personal information and workspace data across the Services.

Last updated: September 15, 2026

Drytis, Inc. — Privacy Policy

Effective Date: September 15, 2026 | Last Updated: September 15, 2026

1. Introduction

Drytis, Inc. ("Drytis," "we," "us," or "our") provides an AI-assisted software development platform that lets users describe an application in plain language and generate a working full-stack product, including frontend, backend, database and authentication, together with hosting and deployment. Where the AI cannot complete part of a build, the platform connects users with vetted Engineers who join the user's Workspace on request and whose Sessions are metered per second.

This Privacy Policy explains what information we collect, how we use and share it, the choices and rights you have, and how we protect it when you visit our websites, including drytis.com and our studio and application subdomains, use the platform, request Engineer Services, or otherwise interact with us (collectively, the "Services"). It also describes how we handle Workspace Content and how artificial intelligence is used within the Services.

This Policy is a notice, not a contract. Your use of the Services is governed by our Terms of Service, our Acceptable Use Policy and, where applicable, our Data Processing Addendum.

2. Scope of This Policy

This Policy applies to personal information we process about visitors to our public websites; Account holders and Authorized Users of the platform, including individual builders, founders and members of team and enterprise Accounts; Engineers who provide services through our network; and business contacts, including prospective customers, partners and applicants.

This Policy does not apply to third-party products, websites or services we do not control, including integrations you connect to your Workspace, or to Deployed Applications you build and operate using Drytis. As Section 11.1 of the Terms provides, you are the operator of your Deployed Applications and are responsible for their privacy practices and for the data your end users provide to them. This Policy also does not govern information about our own personnel, which is addressed in separate employment notices.

3. Definitions

Capitalized terms used in this Policy and not defined here have the meanings given in the Terms of Service, including Workspace Content, Generated Output, Usage Data, Engineer, Engineer Services, Engineer Session Data, Session, Model Training, Deployed Application, Authorized User and Account. Using the contractual definitions keeps this Policy and our agreements aligned.

3.1. "Personal Information" (or "personal data") means information that identifies, relates to, or could reasonably be linked with a particular individual or household.

3.2. "Controller" means the entity that determines the purposes and means of processing personal data.

"Processor" means the entity that processes personal data on behalf of, and under the instructions of, a controller. "Sub-processor" means a third party we engage to process personal data in connection with the Services.

3.3. "Model Provider" means a third-party model provider as described in Section 8.6 of the Terms. Model Providers are Sub-processors.

3.4. "Customer Personal Data" means personal data contained in Workspace Content that we process on a customer's behalf in providing the Services.

3.5. "Data Protection Laws" means the privacy and data-protection laws applicable to our processing, including, where applicable, the EU General Data Protection Regulation (GDPR); the UK GDPR and the Data Protection Act 2018; the Swiss Federal Act on Data Protection (FADP); the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA) and other U.S. state privacy laws;

Canada's PIPEDA and Quebec's Law 25; Brazil's LGPD; Australia's Privacy Act 1988; and India's Digital Personal Data Protection Act, 2023.

3.6. "Sensitive Personal Information" means personal information treated as sensitive or specially protected under applicable Data Protection Laws, including special categories of personal data under the GDPR and Sensitive Personal Information under the CCPA.

3.7. "De-identified" or "aggregated" information means information that cannot reasonably be used to identify an individual, which we maintain in that form and do not attempt to re-identify except as law permits to test the effectiveness of our de-identification.

4. Our Role: Controller and Processor

Our role depends on the data.

4.1. Drytis as controller - We act as a controller, and determine the purposes and means of processing, for Account and registration data, billing and payment data, authentication and security data, support interactions, website and marketing data, Usage Data, the identity-verification and onboarding data described in Section 5.10, the records we maintain under Section 10.10 of the Terms to administer the Direct Engagement Fee, and the Engineer Session Data described in Section 5.4 that is not within Workspace Content. This Policy governs that processing.

4.2. Drytis as processor - We act as a processor, or as a service provider under the CCPA, for Customer Personal Data. We process it on the customer's behalf and on the customer's documented instructions. The customer is the controller, is responsible for the lawful basis for that processing, and is responsible for the rights of its own end users.

Where a Data Processing Addendum applies, it governs our processing of Customer Personal Data and prevails over this Policy in respect of that data. Nothing in this Policy expands or limits what the Addendum permits.

Usage Data is our own data and is not Customer Personal Data. As Section 15.3 of the Terms provides, Usage Data does not include information that retains or is derived from the substantive content of Workspace Content.

5. Information We Collect

We collect information you provide, information generated through your use of the Services, and information we receive from third parties.

5.1. Account and profile information - Your name, email address, username, password in hashed form, organization or team name, role and Account preferences. If you register or sign in through a third-party identity provider, we receive basic profile information from that provider as your settings with it permit.

5.2. Workspace Content - The prompts, instructions, source code, configuration files, datasets, credentials you elect to store, Generated Output and other materials you create, upload or generate within a Workspace.

Workspace Content may contain personal information if you choose to include it. We process it to deliver the build, hosting, deployment, version history and collaboration features you request.

5.3. AI inputs and Generated Output - The Services use large language models to interpret your instructions and produce Generated Output. We process inputs and outputs to deliver the relevant AI functionality, maintain session context, troubleshoot and secure the Services, and prevent abuse. Section 9 describes our position on Model Training.

5.4. Engineer Session Data - When you request Engineer Services, an Engineer joins your Workspace. As Section 9.6 of the Terms provides, we process recordings, logs, chat messages, voice communications, screen activity, audit records, session metadata and Workspace interaction data generated in connection with the Session, together with the Engineer assigned, the actions taken, the duration and metered charges, and any rating or feedback you provide. We process Engineer Session Data to deliver, secure, support and quality- assure Engineer Services, to train our personnel in the delivery of Engineer Services, to investigate abuse and security incidents, to resolve disputes, to substantiate Usage Charges and to comply with law. Access is restricted to authorized personnel. We do not process Session voice or image capture to identify any individual uniquely.

5.5. Usage Data - Telemetry, service-operation data, diagnostics, performance data, logs, usage metrics and configuration metadata generated in connection with your use of the Services, including IP address, browser type and version, operating system, device identifiers, language settings, referring and exit pages, features viewed, build and deployment activity, timestamps, and diagnostic and crash data.

5.6. Payment and billing information - Billing contact details, transaction history, plan, Usage Credits and metered amounts. Card and payment-instrument details are collected and processed by our third-party payment processor and are not stored in full by Drytis. We receive limited information such as a payment token, the last four digits of a card and transaction status, to administer your Account and prevent fraud.

5.7. Communications and support - The content of your communications with us and related metadata, including support requests, survey responses and posts in community channels.

5.8. Cookies and similar technologies - As described in Section 17.

5.9. Information from third parties - Information from identity and authentication providers, payment processors, analytics and security providers, and, if you belong to a team or enterprise Account, from your organization's administrators. We also receive information about business contacts and applicants from publicly available sources.

5.10. Identity verification and Sensitive Personal Information - To operate the Engineer network, meet legal obligations and prevent fraud, we or our verification vendors collect identity and verification information from Engineers and, where required, from Account holders. This can include government-issued identification, verification or liveness images, tax and payment-onboarding details, and background- screening results where law permits. We use identity documents, verification information and, where applicable, liveness information solely for identity verification, fraud prevention, security, onboarding and legal-compliance purposes described above. We do not use such information to infer characteristics about an individual or for advertising or unrelated profiling. Sensitive Personal Information is collected only where necessary for verification, security or legal compliance, subject to applicable law and appropriate safeguards.

5.11. We do not intend to receive special-category data or Sensitive Personal Information through Workspace Content. Section 17.5 of the Terms prohibits submitting it unless we have designated the relevant Service as approved for that category and the parties have executed any additional agreement it requires.

6. Categories of Personal Information — Notice at Collection

6.1. This Policy is our notice at collection under California and comparable laws. In the preceding twelve months we have collected the following statutory categories: identifiers, including name, email, username, IP address and Account and device identifiers; customer records and commercial information, including billing details and transaction history; internet and network activity, including Usage Data and diagnostic data; audio, electronic and visual information, including Session recordings and communications; professional or employment information, for business contacts and Engineers; geolocation inferred from IP address;

Sensitive Personal Information as described in Section 5.10; and personal information contained in Workspace Content you choose to provide.

6.2. The sources of that information are described in Section 5, the purposes in Section 7, the categories of recipients in Section 12, and our retention approach in Section 14.

6.3. We do not sell personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under applicable law. We do not use or disclose Sensitive Personal Information beyond the purposes applicable law permits.

7. How We Use Information

We use the information described above to:

• provide and operate the Services — authenticate you, generate and host applications, maintain version history, enable deployment, and connect you with Engineers;

• process AI requests — interpret prompts and produce Generated Output;

• deliver Engineer Services — assign Engineers, facilitate Sessions, and meter and substantiate Usage Charges;

• verify identity and eligibility — onboard and screen Engineers, verify Accounts where required, and prevent fraud and impersonation;

• process payments — administer plans, invoices, Usage Charges, refunds and fraud prevention, and administer the Direct Engagement Fee under Section 10.10 of the Terms;

• communicate with you — send service, security and administrative messages and, where permitted, marketing you can opt out of;

• support and improve the Services — respond to requests, diagnose problems, conduct analytics and develop features;

• maintain quality and safety — monitor for abuse, fraud and prohibited use, quality-assure Engineer Services, and enforce the Terms and the Acceptable Use Policy, as Section 13 of that Policy provides;

• secure the Services — detect, investigate and prevent security incidents and unauthorized activity; and

• comply with law — meet legal obligations, respond to lawful requests, and establish, exercise or defend legal claims.

8. Artificial Intelligence and Automated Processing

8.1. Inputs, outputs and Model Providers - Your inputs and the resulting Generated Output are processed to deliver the feature, maintain session context, and operate and secure the platform. Some AI functionality is delivered through Model Providers, which are Sub-processors. As Section 2.6 of the Data Processing Addendum provides, we contractually require each Model Provider that processes Customer Personal Data to process it only to provide the relevant capability to us and not to conduct Model Training on it.

8.2. Human review - We do not routinely read your Workspace Content. Human review occurs where you request Engineer Services, where you contact support, where review is necessary to investigate abuse or a security or legal issue, or where you otherwise direct us to access your Workspace.

8.3. Abuse and security monitoring - As Section 13 of the Acceptable Use Policy provides, we use automated and, where necessary, manual means to identify activity that violates the Terms or that Policy, such as attempts to generate malware or other prohibited content. We have no obligation to monitor Workspace Content.

8.4. Automated decision-making - Generating code and other output in response to your instructions is not a decision about you. Generated Output is a tool you direct, and as Section 6.2 of the Terms provides, you are responsible for reviewing it before relying on it.

We use automated systems to flag suspected fraud, abuse and security risk. Where a resulting enforcement decision would significantly affect you such as suspension or termination of an Account under Section 20.2 or Section 20.5 of the Terms a person reviews the matter before the decision becomes final, except where immediate action is necessary to prevent harm, protect the security or integrity of the Services, or comply with law, in which case we review promptly afterwards. You may contest such a decision by contacting us as described in Section 24, and we will tell you the principal reasons for it to the extent doing so would not compromise a security or fraud investigation.

8.5. We do not otherwise make decisions producing legal or similarly significant effects about you by automated means alone. If we introduce a feature that would do so, we will provide the required disclosures and honour the applicable opt-out or human-review rights before it operates.

9. Model Training

9.1. We do not use Workspace Content including prompts, source code, uploaded files, datasets and Generated Output for Model Training, and we do not authorize any Sub-processor or Model Provider to do so, unless you expressly authorize it in writing. This reflects Section 7.4 of the Terms and Section 2.7 of the Data Processing Addendum.

9.2. Where you grant that authorization, we process the data only within the scope, for the purposes, and for the retention period the authorization specifies, and you may withdraw it prospectively at any time. Withdrawal does not require us to retrain or reverse a model already modified in reliance on it. No de-identification, aggregation, pseudonymization or other transformation of Workspace Content is used to work around this restriction.

9.3. To operate and improve the Services, we use Usage Data and aggregated, or de-identified information derived from operation of the Services and not from the substantive content of Workspace Content, on the terms of Section 15.3 of the Terms. We maintain that information in a form that cannot reasonably identify you, do not attempt to re-identify it except as law permits to test our de-identification, and require recipients to accept the same restriction.

9.4. Enterprise and team customers are subject to the data-use terms in their agreement, which prevail over this Section for their data.

10. Engineers and Confidentiality

Engineers are vetted before they join the network. When you request Engineer Services, the assigned Engineer receives access only to the Workspace and context needed for your request, and only for the duration of the Session, consistent with Sections 9.2 through 9.4 of the Terms.

Engineers are employees or contractors of Drytis, not your employees or agents, and are bound by written confidentiality obligations under Section 9.7 of the Terms and by the Acceptable Use Policy. We apply least- privilege and need-to-know controls, log Session access, revoke access on completion, and may suspend or remove Engineers who violate our standards. This session may be recorded for security, quality assurance, billing and support purposes.

Where the GDPR, UK GDPR or FADP applies to our processing as a controller, we rely on:

• performance of a contract, to provide the Services you request, including Account, build, hosting, deployment and Engineer Services features, and to process payments;

• legitimate interests, to operate, secure, analyze and improve the Services, prevent fraud and abuse, administer the Direct Engagement Fee, and conduct direct marketing to business contacts, in each case balanced against your rights and interests;

• legal obligation, to comply with applicable law and respond to lawful requests; and

• consent, where law requires it, including for non-essential cookies and certain marketing. You may withdraw consent at any time, without affecting processing carried out before withdrawal.

Where verification or screening information described in Section 5.10 unavoidably includes a special category of personal data, we rely on Article 9(2)(f) of the GDPR, for the establishment, exercise or defense of legal claims, and on the corresponding provisions of the UK GDPR and the FADP. We do not process identity documents or verification images to identify an individual uniquely.

Where we act as a processor for a customer, that customer is responsible for establishing the legal basis for the personal data it processes through the Services.

12. How We Share Information

We do not sell personal information. We disclose it only as follows.

12.1. Sub-processors - Cloud hosting and infrastructure, Model Providers, payment processing, analytics and error monitoring, customer support tooling, email delivery and security vendors. Each is authorized to process personal information only as needed to perform services for us, under written confidentiality and data-protection obligations no less protective than those we owe. We maintain a current list of Sub- processors and, for customers subject to the Data Processing Addendum, provide advance notice of additions and an opportunity to object, as Sections 5.1 and 5.3 of that Addendum provide.

12.2. Engineers - The assigned Engineer receives the Workspace access and context necessary for your request, on the terms in Section 10.

12.3. Within your organization - If you use a team or enterprise Account, your administrators and authorized members may access Account and Workspace information consistent with their permissions.

12.4. Legal and safety - We disclose information to comply with law, regulation, legal process or a lawful governmental request; to enforce the Terms and the Acceptable Use Policy; or to protect the rights, property or safety of Drytis, our users or others. Where we hold the information as a processor and are legally permitted to do so, we notify the customer and redirect the requesting party to it, as Section 12 of the Data Processing Addendum provides. This does not apply to, and does not delay, our reporting and preservation obligations in respect of apparent child sexual abuse material.

12.5. Business transfers - As described in Section 22.

12.6. At your direction - Integrations and third-party services you connect, as described in Section 21.

We have not sold personal information and have not shared it for cross-context behavioral advertising, in the preceding twelve months, and we will not do so without first providing the notice and opt-out that law requires.

13. International Data Transfers

Drytis is established in the United States and offers the Services globally. Your information may be transferred to, stored in and processed in the United States and in other countries where we, our affiliates or our Sub-processors operate, which may have data-protection laws different from those of your jurisdiction.

13.1. Transfers of Customer Personal Data - Where we process Customer Personal Data as a processor, transfers are governed by Section 11 and Appendix 4 of the Data Processing Addendum, which incorporates the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, and the Swiss adaptations required by the Federal Data Protection and Information Commissioner.

13.2. Transfers of data we hold as controller - Where we transfer personal data from the EEA, the United Kingdom or Switzerland to a country that has not been found to provide an adequate level of protection, we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or the Swiss adaptations to those Clauses, together with supplementary measures where an assessment indicates they are needed. Where we hold and maintain an active self-certification under the EU- U.S. Data Privacy Framework, its UK Extension, or the Swiss-U.S. Data Privacy Framework, we may rely on that certification for the transfers it covers; if a certification lapses or is withdrawn, the Standard Contractual Clauses apply to those transfers.

Where personal data is transferred outside Quebec, we conduct the privacy impact assessment and put in place the written agreement that Law 25 requires.

You may request further information about these safeguards using the details in Section 24.

14. Data Retention

We retain personal information for as long as needed to provide the Services, maintain your Account and Workspaces, comply with legal obligations, resolve disputes and enforce our agreements. Retention varies by data type and context:

• Account and Workspace data is retained while your Account is active and for the periods described below, then deleted or de-identified;

• AI inputs and Generated Output are retained as needed to operate and secure the feature and maintain session context, then deleted or de-identified on a rolling basis;

• Engineer Session Data, including recordings, is retained for quality assurance, dispute resolution, billing substantiation and security, then deleted;

• billing records are retained as tax, accounting and legal requirements demand; and

• Usage Data and diagnostic logs are retained for limited periods for security and operational needs.

On expiration or termination, Section 20.7 of the Terms gives you thirty days to export your Workspace Content, reduced to not less than seven days under a supervised process where we terminate for cause under Section 20.5(b).

After that period we may delete Workspace Content from our active systems. Where the Data Processing Addendum applies, Section 9 of that Addendum governs deletion and return of Customer Personal Data.

Backup and disaster-recovery copies persist until deleted or overwritten in the ordinary course and are not actively processed except for restoration, security or legal compliance. We may retain information for longer where law requires it or where it is reasonably necessary to resolve a dispute, enforce our agreements, or protect the security and integrity of the Services.

15. Security

15.1. We maintain administrative, technical and organizational measures designed to protect personal information against unauthorized access, disclosure, alteration and destruction. These include encryption of data in transit and at rest, role-based and least-privilege access controls, multi-factor authentication for administrative access, scoped and time-limited Engineer Session access, logging and monitoring, vulnerability management, a documented incident-response process, and Workspace version history that allows you to revert to an earlier state. Section 4 and Appendix 2 of the Data Processing Addendum set out our security commitments for Customer Personal Data.

15.2. No method of transmission or storage is completely secure, and we do not guarantee absolute security. As Section 18.2 of the Terms provides, security is a shared responsibility: you are responsible for your own configuration and use of the Services, including access management, credential and secrets hygiene, integration scopes and Session-access controls, and for notifying us promptly of any suspected unauthorized use of your Account.

15.3. If we become aware of a security incident affecting personal information for which we are the controller, we will notify affected individuals and the competent supervisory authority where and within the time applicable law requires. Where the incident affects Customer Personal Data that we process on a customer's behalf, we notify that customer without undue delay under Section 7 of the Data Processing Addendum and Section 17.6 of the Terms, and the customer determines any notification to individuals or authorities.

16. Your Privacy Rights and Choices

16.1. General choices - You can access and update much of your Account information through your Account settings. You can opt out of marketing email using the unsubscribe link; we will still send service, security and administrative messages. You can manage cookies as described in Section 17.

16.2. How to exercise your rights - Contact us using the details in Section 24, or use in-product controls where offered. We respond within the period applicable law requires, and will tell you if we need an extension the law permits. We take reasonable steps to verify your identity before acting and may decline requests we cannot verify or that are manifestly unfounded, excessive or repetitive. You may use an authorized agent where the law allows, subject to verification. We will not discriminate or retaliate against you for exercising your rights.

If we decline a request, we will explain why. Where applicable law provides a right of appeal, you may appeal by contacting us at legal@drytis.com, and if we deny the appeal we will tell you how to complain to your state attorney general or supervisory authority.

Where we hold the information as a processor for a customer, we will refer your request to that customer and assist it in responding.

16.3. EEA, UK and Switzerland - Subject to applicable law, you may request access to, correction of, deletion of, and a portable copy of your personal data; restrict or object to certain processing, including direct marketing; withdraw consent where processing is based on consent; and lodge a complaint with your supervisory authority — in the United Kingdom, the Information Commissioner's Office, and in Switzerland, the Federal Data Protection and Information Commissioner.

16.4. California. If you are a California resident, you may request to know the categories and specific pieces of personal information we have collected, together with the sources, purposes and categories of recipients; request deletion and correction; and be free from discrimination for exercising your rights. You may direct us not to sell or share your personal information and to limit our use of Sensitive Personal Information; we do not sell or share personal information, and we already limit our use of Sensitive Personal Information to the purposes law permits, so no action is required, but you may submit a request. This Policy is our notice at collection, and Section 16.2 describes how to appeal a denied request.

16.5. Other U.S. states - Residents of other states with comprehensive privacy laws may have rights to access, correct, delete and obtain a portable copy of their personal information, and to opt out of targeted advertising, sale and profiling in furtherance of decisions producing legal or similarly significant effects. We honour those rights as applicable state law requires. We recognize a valid universal opt-out preference signal, including Global Privacy Control, as an opt-out request for the browser or device from which it is sent.

Nevada residents may direct us not to sell covered information; we do not sell it.

16.6. Canada, Brazil, Australia and other jurisdictions - If you are in Canada, you may access and correct your personal information and withdraw consent, subject to legal and contractual restrictions, and in Quebec you also have rights to data portability and to information about automated decision-making. You may complain to the Office of the Privacy Commissioner of Canada or, in Quebec, to the Commission d'accès à l'information.

If you are in Brazil, you may obtain confirmation of processing, access, correction, anonymization, blocking or deletion of unnecessary or excessive data, portability, information about sharing, and withdrawal of consent, and you may complain to the Autoridade Nacional de Proteção de Dados. Our contact for LGPD purposes is the address in Section 24.

Residents of other jurisdictions, including Australia and India, may have rights under their local Data Protection Laws. We honour applicable rights and respond to verified requests as law requires.

17. Cookies and Similar Technologies

We use cookies and similar technologies to keep you signed in, remember preferences, secure the Services, measure performance and understand usage. We classify them as:

• strictly necessary — required to operate the Services and authenticate you;

• functional — to remember your settings and preferences; and

• analytics — to understand how the Services are used so we can improve them.

Strictly necessary cookies are set without consent. In the EEA, the United Kingdom and Switzerland, we set functional and analytics cookies only with your prior consent, obtained through our consent tool, and you may withdraw consent or change your choices at any time through that tool. Elsewhere, you may manage cookies through the same tool and through your browser settings, though browser settings alone do not control everything and disabling some cookies may affect functionality.

We recognize a valid opt-out preference signal, including Global Privacy Control, where applicable law requires, and treat it as an opt-out for the browser or device from which it is sent. We do not use cookies to serve third-party targeted advertising.

18. Children's Privacy

The Services are intended for users aged eighteen or older and are not directed to children. We do not knowingly collect personal information from anyone under eighteen. If we learn that we have, we will delete it. If you believe a person under eighteen has provided us with personal information, contact us using the details in Section 24.

Separately, you are responsible for any children's personal information contained in Workspace Content or processed by a Deployed Application you operate. Section 17.5 of the Terms prohibits submitting personal information subject to the Children's Online Privacy Protection Act or comparable law unless we have designated the relevant Service as approved for it and the parties have executed any additional agreement it requires.

19. Team and Enterprise Accounts

If you use the Services through an organization's team or enterprise Account, that organization controls the Account and the Workspace Content within it. Its administrators may access, manage, restrict or remove your access and view information associated with your use of the Account, as Section 3.4 of the Terms provides. Your use is also subject to your organization's policies, and questions about how it handles your data should be directed to your administrator. For those customers, our processing of personal data within Workspace Content is governed by the applicable agreement and Data Processing Addendum.

20. APIs and Developer Functionality

If you use our APIs or developer tools, or build agentic or Model Context Protocol applications on the platform, we process authentication credentials such as API keys and access tokens, request and usage metadata, and the content you transmit through those interfaces, in order to operate, secure, rate-limit and bill for the relevant functionality. As Section 3.2 of the Terms provides, you are responsible for securing your credentials, and you are responsible for the lawful use of any data you transmit, including data relating to your own end users.

21. Third-Party Services and Integrations

The Services let you connect third-party tools and integrations to your Workspace and may link to third-party websites. When you enable an integration, you instruct us to transmit and receive the data necessary to operate it within the scope you authorize, and Section 12.2 of the Terms governs that provider's handling of the data once transmitted. Services you connect are not Drytis Sub-processors, and their use of your information is governed by their own privacy policies. We are not responsible for the privacy practices of third parties, and we encourage you to review the policies of any service you connect or visit.

22. Business Transfers

If Drytis is involved in a merger, acquisition, financing, reorganization, bankruptcy or sale of all or part of its assets, personal information may be transferred as part of that transaction. We will take reasonable steps to ensure that the transfer is conducted in accordance with applicable law and that protections consistent with this Policy continue to apply.

23. Changes to This Policy

We update this Policy from time to time to reflect changes in our practices, technology or legal requirements. We will revise the "Last Updated" date above and, for material changes, provide notice through the Services or by email in accordance with Section 1.6 of the Terms. Where applicable law requires your consent to a change, we will obtain it before the change applies to you. Changes take effect on the date stated in the notice.

24. Contact Us

For questions about this Policy or our privacy practices, or to exercise your rights:

Drytis, Inc.

Attn: Privacy Team Email: legal@drytis.com 1985 Riviera Dr, Ste 103 - 1033, Mount Pleasant, SC 29464, United States