Sixty8 Inc. Legal Center

Privacy Policy

This Privacy Policy explains how Sixty8 Inc. collects, uses, discloses, protects, and otherwise processes information in connection with our website, professional Services, software, integrations, Leverage services, referrals, connected systems, and Client Portal.

Effective: September 13, 2026 Version 1.2 Sixty8 Inc.
Your privacy matters. This Policy describes Sixty8 Inc.'s general privacy practices. Individual projects, applications, subscriptions, Leverage services, referral programs, connected systems, or other Services may include additional privacy notices, contractual restrictions, or data-processing terms where their processing activities require more specific disclosures.
Section 01

Introduction

Sixty8 Inc. ("Sixty8," "we," "our," or "us") respects the privacy of individuals who visit our website, communicate with us, use our Client Portal, subscribe to or use Leverage, participate in the Sixty8 Referral Program, purchase Services, interact with applications operated by us, connect authorized systems, or otherwise provide information to us.

This Privacy Policy explains our general practices concerning personal information. "Personal information" means information that identifies, relates to, describes, or may reasonably be associated with an identifiable individual, as defined under applicable law.

Section 02

Scope of This Policy

This Policy may apply to information collected through:

  • Sixty8 websites and online forms;
  • Project inquiries and consultations;
  • Referral submissions, introductions, and business recommendations;
  • Project onboarding;
  • The Sixty8 Client Portal;
  • Leverage subscriptions and interfaces;
  • AI-assisted and human-assisted execution Services;
  • Connected systems authorized by Clients;
  • Approval workflows and task execution;
  • Support and customer-service communications;
  • Proposals, contracts, invoices, and project records;
  • Applications or software operated by Sixty8 where this Policy is presented;
  • AI and automation features operated by Sixty8;
  • Payment and billing interfaces;
  • Email and other business communications; and
  • Related Sixty8 Services.

A product, Client-specific system, enterprise relationship, or particular Service may be subject to a separate or supplemental privacy notice, Data Processing Agreement, confidentiality agreement, or other contractual privacy terms.

When Sixty8 processes information solely on behalf of a Client in connection with a Client-owned application, Connected System, or service, the Client may be responsible for determining the purposes and means of that processing, and the Client's own privacy policy may apply.

Section 03

Information We Collect

Identity & Contact Information

We may collect your name, email address, telephone number, business name, job title, mailing address, and similar contact information.

Referral & Introduction Information

We may collect information provided by another person when they make a referral, introduction, or business recommendation to Sixty8. This information may include your name, business or organization, email address, telephone number, website, potential service interests, the nature or timing of a possible business need, and contextual information supplied by the person making the referral.

We may also collect information about the person making the referral, including their name, contact information, relationship to Sixty8, and information necessary to maintain referral attribution and administer the Sixty8 Referral Program.

Account Information

We may collect usernames, account identifiers, authentication information, account preferences, permissions, roles, authorization levels, and related account records.

Project & Business Information

We may collect project requirements, business plans, product information, design preferences, technical requirements, branding materials, content, files, documents, approvals, communications, business records, and other information needed to provide Services.

Billing & Transaction Information

We may collect billing names, addresses, invoice information, payment status, transaction identifiers, purchased Services, subscription information, account balances, usage-based charges, and related financial records.

Technical Information

Depending on the Service, we may collect IP addresses, browser type, device type, operating system, referring pages, access dates, session information, error logs, application logs, integration logs, execution logs, and security-related information.

Client Portal & Leverage Information

We may process project messages, files, invoices, approvals, contracts, support requests, task requests, workflow instructions, execution history, authentication activity, audit records, permission settings, integration configuration, and other information submitted through or generated by the Client Portal or Leverage.

Connected-System Information

Where a Client authorizes access to a third-party or Client-controlled system, we may process information available through the authorized connection, including records, files, messages, account information, technical data, configuration information, and other content necessary to perform the requested Services.

Credentials, Tokens & Authorization Data

Depending on the integration, we may process OAuth tokens, API credentials, service-account information, authorization grants, scoped access tokens, integration identifiers, or other technical information used to establish or maintain authorized connections.

Where reasonably available, Sixty8 may use delegated or scoped access mechanisms instead of primary account passwords.

AI & Automation Information

Depending on the feature, we may process prompts, instructions, responses, uploaded files, configuration information, standing rules, workflow data, AI-generated output, automated actions, approval status, usage records, or other information submitted to or generated by AI-enabled Services.

Human-Assisted Service Information

Where a request is reviewed, escalated, corrected, or performed by Sixty8 personnel, authorized personnel may access information reasonably necessary to perform the requested work, provide support, investigate an issue, or complete an approved task.

Communications

We may retain communications with you, including emails, support messages, meeting notes, project discussions, instructions, approval messages, and feedback.

Section 04

How We Collect Information

We may collect information:

  • Directly from you;
  • From an authorized representative of your organization;
  • When you create or use an account;
  • When you subscribe to or configure Leverage;
  • When you submit forms, referrals, introductions, or project information;
  • From another person who submits a referral or business introduction concerning you or your organization;
  • When you provide instructions, approvals, or workflow rules;
  • Automatically through websites, servers, applications, logs, cookies, or similar technologies;
  • Through integrations or Connected Systems you authorize;
  • Through OAuth, APIs, service accounts, or other approved access mechanisms;
  • From payment, hosting, cloud, AI, communications, or other service providers;
  • From publicly available sources where appropriate; and
  • During the ordinary course of providing Services.

From Referrers & Business Contacts

We may receive personal information about you from another person who submits a referral, makes an introduction, or recommends your business or organization to Sixty8. A referral does not automatically mean that Sixty8 will contact you, and we may evaluate whether outreach is appropriate before using the information for direct communication.

Section 05

How We Use Information

We may use personal information to:

  • Respond to inquiries;
  • Evaluate prospective projects;
  • Evaluate referrals, introductions, and potential business opportunities;
  • Determine whether outreach to a referred person or organization is appropriate;
  • Maintain referral source attribution and administer referral eligibility;
  • Prevent duplicate, fraudulent, abusive, or conflicting referral claims;
  • Provide and administer Services;
  • Create and manage Client accounts;
  • Operate the Client Portal;
  • Operate and administer Leverage;
  • Configure and maintain authorized integrations;
  • Process Client instructions and workflows;
  • Perform authorized AI or automated actions;
  • Route work for human review or execution;
  • Manage approval workflows;
  • Maintain execution and activity records;
  • Design and develop Client projects;
  • Process billing and maintain financial records;
  • Authenticate users;
  • Provide support;
  • Manage contracts and approvals;
  • Operate software and integrations;
  • Detect and investigate security events;
  • Prevent fraud and misuse;
  • Debug, maintain, and improve our systems;
  • Analyze Service performance and usage;
  • Communicate administrative or Service information;
  • Protect our legal rights;
  • Comply with legal obligations; and
  • Carry out other purposes disclosed when information is collected.

Referral information is used to evaluate and administer the referral relationship and related business opportunity. Submission of a referral does not guarantee that Sixty8 will contact the referred party, accept the opportunity, or determine that a referral reward is eligible.

Section 06

Client Portal, Leverage & Connected-System Data

The Client Portal and Leverage may contain confidential business information, project files, communications, invoices, contracts, Deliverables, task instructions, workflow configurations, support records, permission settings, approval records, integration information, and other Client information.

Authorized Access

Where a Client connects or authorizes access to a system, Sixty8 may process information from that system to the extent reasonably necessary to provide the requested Service, execute authorized tasks, maintain an integration, or troubleshoot the connection.

Permissions & Approvals

Leverage may process information concerning Client-configured access permissions, action permissions, approval requirements, authorized users, standing instructions, and human-review settings.

Activity Records

We may maintain logs concerning Client Portal and Leverage activity, including authentication events, requests, instructions, approvals, AI processing, human intervention, system access, executed actions, errors, communications, and security events.

These records may be used for authentication, security, fraud prevention, support, billing, auditing, troubleshooting, quality assurance, dispute resolution, and recordkeeping.

Business Client Administration

Business Clients are responsible for controlling which personnel are authorized to use their accounts, which Connected Systems may be accessed, and what permissions those users or systems receive.

Clients should promptly update or revoke permissions when personnel, credentials, responsibilities, or authorization change.

Use of Leverage is also subject to the Leverage Service Terms .
Section 07

Payment & Financial Information

Payment processors may collect payment credentials directly. Depending on the payment method and integration, Sixty8 may not receive or store the complete payment-card number or other sensitive authentication data.

Transactions and subscription payments may be processed through independent payment gateways, merchant processors, banks, or payment service providers.

We may receive information associated with those transactions, including transaction identifiers, status, amount, billing information, subscription plan, payment method type, limited account information, and records necessary for accounting, support, fraud prevention, subscription administration, or project administration.

Payment providers process information according to their own terms and privacy policies.

Section 08

Artificial Intelligence & Automated Technologies

Certain Sixty8 Services or Client projects may use artificial intelligence, machine learning, generative models, computer vision, automated workflows, AI agents, autonomous or supervised execution, or third-party AI APIs.

Information Submitted to AI Systems

Information submitted to an AI-enabled feature may be processed to generate responses, classifications, summaries, recommendations, content, code, images, automation actions, task plans, or other requested output.

AI-Assisted Actions

Where authorized, AI systems or automated workflows may process information from Connected Systems in order to retrieve information, create or update records, prepare communications, modify authorized files, interact with APIs, trigger workflows, update websites, or perform other Client-authorized actions.

Human Review & Human Execution

Some AI-enabled requests may be reviewed, corrected, escalated, or completed by Sixty8 personnel. This may require authorized personnel to access the information reasonably necessary to perform the requested Service.

The availability of human support does not mean that every AI-generated output or automated action is reviewed by a human.

Third-Party Providers

Some AI implementations may involve independent AI, cloud, infrastructure, or software providers. Information provided to those providers may be processed according to the contractual configuration selected for the applicable project or Service and the provider's governing terms.

Client-Specific Restrictions

Where a Client requires special restrictions regarding retention, model training, confidentiality, data location, logging, provider selection, subprocessors, or use of regulated information, those restrictions should be expressly documented in the applicable Project Agreement, Data Processing Agreement, or other controlling written agreement.

Automated Decisions

Unless expressly disclosed and lawfully configured for a particular Service, Sixty8 does not intend general website or Leverage AI features to autonomously make final legally binding or similarly significant decisions about individuals without appropriate human involvement.

Section 09

Cookies & Similar Technologies

Our website and online Services may use cookies, local storage, pixels, session technologies, or similar technologies to operate features, remember preferences, maintain sessions, improve security, analyze performance, and understand how Services are used.

These technologies may include:

  • Essential technologies needed for site or account operation;
  • Security technologies used for authentication and fraud prevention;
  • Preference technologies used to remember settings;
  • Analytics technologies used to understand performance and usage; and
  • Advertising technologies, if implemented and disclosed.

Available cookie controls may vary depending on the technologies deployed on our website.

Section 10

How We Disclose Information

We may disclose information to third parties where reasonably necessary for legitimate business and Service purposes, including:

  • Cloud and hosting providers;
  • Payment processors;
  • AI and machine-learning providers;
  • Software and infrastructure providers;
  • Integration and API providers;
  • Authentication and identity providers;
  • Analytics and security providers;
  • Communication and customer-support providers;
  • Professional advisers such as attorneys and accountants;
  • Contractors or specialists assisting with authorized projects or Leverage requests;
  • Government or legal authorities where disclosure is lawfully required; and
  • Parties involved in an authorized merger, acquisition, financing, reorganization, or transfer of business assets.

We may also disclose information with your direction, authorization, or consent, including where an authorized Leverage workflow requires information to be transmitted to a Connected System or third-party service selected by the Client.

Where reasonably necessary to administer a referral, commission, service credit, or service grant, Sixty8 may use or disclose limited referral information to the relevant participant, recipient, payment provider, tax professional, or service provider. A referrer does not receive unrestricted access to the referred party's communications, project records, account information, or other confidential information merely because the referral was submitted.

Section 11

Sale & Sharing of Personal Information

Sixty8 does not intend to sell personal information to third parties in exchange for monetary payment as part of its ordinary professional services or Leverage business.

Certain privacy laws define terms such as "sell," "share," or "targeted advertising" more broadly than an ordinary monetary sale.

If Sixty8 implements advertising or tracking technologies that create additional opt-out obligations under applicable law, we will provide required controls or disclosures.

Where applicable, qualifying users may contact us using the privacy request information below to exercise available rights concerning sale or sharing.

Section 12

Data Retention

We retain information for periods reasonably necessary for the purposes for which it was collected, including Service delivery, project administration, subscription administration, account management, execution history, contractual obligations, legal compliance, security, dispute resolution, financial recordkeeping, backup processes, and enforcement of agreements.

Retention periods may vary depending on the nature of the information, the Service involved, contractual requirements, security requirements, technical requirements, Client configuration, and applicable legal obligations.

Referral Records

Referral records may be retained for a reasonable period to preserve source attribution, resolve duplicate or competing referral claims, administer earned rewards, maintain accounting or tax records, prevent abuse, and document the history of a related business opportunity.

Connected-System Data

Information retrieved from a Connected System may be processed transiently, cached, logged, stored, or retained depending on the functionality being performed and the technical requirements of the Service.

Credentials & Tokens

Authorization tokens, service credentials, or other technical integration data may be retained for as long as reasonably necessary to maintain an authorized integration, unless earlier revoked or deleted.

Offboarding

Following termination of a Service, Sixty8 may disable integrations, revoke Sixty8-controlled credentials, stop workflows, and begin applicable deletion or retention processes in accordance with contractual and legal requirements.

Information may remain temporarily in backups or archival systems after deletion from active systems where immediate removal is not technically practicable.

Section 13

Data Security

Sixty8 uses administrative, technical, and organizational safeguards that we consider reasonable and appropriate in light of the nature of the information and Services involved.

Depending on the system, safeguards may include access controls, authentication, encryption, monitoring, backups, logging, network protections, software updates, scoped credentials, delegated authorization, token management, or other technical and operational measures.

Access Controls

Where supported, Sixty8 may use permission scopes, Client-configured authorization levels, approval gates, role-based access, or other controls intended to limit access and execution to authorized purposes.

Credentials

Clients should grant only the level of access reasonably necessary for the applicable Service and should promptly revoke access when it is no longer required.

No method of transmission, storage, network operation, integration, software application, AI service, or electronic security can be guaranteed to be completely secure.

Users are responsible for protecting their own account credentials and notifying us promptly if unauthorized access or credential compromise is suspected.

Section 14

Your Privacy Choices & Rights

Depending on your location and the law applicable to Sixty8's processing, you may have rights concerning your personal information.

These may include rights to:

  • Request access to certain personal information;
  • Request correction of inaccurate information;
  • Request deletion of qualifying information;
  • Obtain certain information in a portable form;
  • Object to or restrict certain processing;
  • Withdraw consent where processing relies on consent;
  • Opt out of qualifying sale, sharing, or targeted advertising;
  • Limit certain uses of sensitive personal information where applicable; and
  • Appeal certain privacy-request decisions where applicable.

These rights are not absolute and may be subject to verification, statutory exceptions, contractual requirements, technical limitations, or other legal limitations.

Sixty8 will not unlawfully discriminate against an individual for exercising an applicable privacy right.

Section 15

U.S. State Privacy Rights

Residents of certain U.S. states may have additional privacy rights under applicable state law.

California

If the California Consumer Privacy Act and related California privacy requirements apply to Sixty8's processing of your information, you may have additional rights concerning access, correction, deletion, portability, and qualifying sale or sharing of personal information, subject to statutory conditions and exceptions.

We may be required to verify your identity before completing certain privacy requests. An authorized agent may submit a request where permitted by law, subject to required verification.

Other States

Where another state privacy law provides applicable rights, Sixty8 will process qualifying requests in accordance with the law that applies to the request.

Section 16

International Visitors

Sixty8 is based in the United States. If you access our Services from another country, information may be processed or stored in the United States or other countries where Sixty8 or its service providers operate.

AI providers, cloud providers, Connected Systems, and other third-party services selected or authorized for a particular implementation may process information in additional locations.

Where required for a specific project or jurisdiction, Sixty8 may provide supplemental privacy terms or implement appropriate contractual or technical measures concerning international data processing.

Section 17

Children's Privacy

Sixty8's general business website, Leverage service, and professional Services are not directed to children under 13, and we do not knowingly seek to collect personal information directly from children under 13 through our general business Services.

If a Client engages Sixty8 to develop or operate a product intended for children or minors, privacy requirements applicable to that specific product must be addressed separately as part of the project.

If you believe a child has submitted personal information to Sixty8 through our general business Services without appropriate authorization, contact us using the information below.

Section 18

Third-Party Websites & Services

Our Services may link to or integrate with independent websites, payment processors, social platforms, hosting providers, AI providers, cloud services, APIs, software services, communication systems, Client-authorized Connected Systems, and other third parties.

Where a Client instructs Leverage or Sixty8 to interact with a third-party service, information may be transmitted to or retrieved from that service as reasonably necessary to perform the authorized action.

Sixty8 is not responsible for the independent privacy practices of third parties. You should review their privacy notices when appropriate.

Section 19

Security Incidents

If Sixty8 discovers a security incident involving information under its control, we will investigate and respond based on the nature and scope of the incident and will provide notifications where required by applicable law or contractual obligation.

Clients should promptly notify Sixty8 if they believe an account, credential, integration, authorization token, or Connected System associated with Sixty8 Services has been compromised or accessed without authorization.

Sixty8 may temporarily suspend an affected integration, workflow, credential, or account where reasonably necessary to investigate or reduce security risk.

Section 20

Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect changes to our Services, Leverage capabilities, Referral Program, technologies, integrations, business practices, providers, or legal requirements.

When the Policy is updated, we will revise the effective date and version shown at the top of this page. Where additional notice is required by law, we will provide that notice through an appropriate method.

Section 21

Contact Us & Privacy Requests

Questions, privacy inquiries, or requests to exercise applicable privacy rights may be directed to:

Sixty8 Inc.
Attn: Privacy
115 W Pleasant St. Suite 7
Maquoketa, Iowa 52060
United States

Privacy: privacy@sixty8inc.com
Support: support@sixty8inc.com

We may request information reasonably necessary to verify the identity or authority of a person submitting a privacy request.

Referral Program. Participation in the Sixty8 Referral Program is also subject to the Referral Program Terms .