INVENTORY DI PRIVACY POLICY

Effective Date: August 30, 2026 

Inventory DI (“Inventory DI,” “we,” “us,” or “our”) is a business-to-business inventory accountability and field operations platform. This Privacy Policy explains how personal information is collected, used, disclosed, retained, transferred, and protected in connection with our websites, web applications, mobile applications, demonstrations, support, communications, and related services (collectively, the “Services”).

Operator / Legal Entity: Inventory DI, LLC doing business as or operating Inventory DI.

Principal Business 5818 Max Dr., Waterville, Ohio 43566

This Policy is designed to provide a global privacy framework. Additional rights or obligations may apply depending on where you live, where your employer or organization operates, and the nature of the processing. Where applicable law provides greater protection than this Policy, we will comply with that law.

1. Scope and Our Privacy Roles

1.1 When Inventory DI acts as a controller or business

Inventory DI generally determines the purposes and means of processing when we handle information about website visitors, prospective customers, customer administrators, business contacts, billing contacts, support contacts, and individuals who interact directly with us for our own business purposes. In those situations, Inventory DI acts as a “controller,” “business,” or similar responsible party under applicable privacy law.

1.2 When Inventory DI acts as a processor or service provider for customers

A customer organization may provide, create, or generate information about its employees, contractors, coordinators, third parties, jobsites, vehicles, warehouses, inventory activity, and operational workflows through the Services (“Customer Data”). For Customer Data that we process only on the customer’s documented instructions, the customer generally acts as the controller/business and Inventory DI acts as a processor/service provider. The customer determines why the data is processed, which users may access it, how long it should be retained, and what workplace notices or permissions are required, subject to the customer agreement and applicable law.

If you use Inventory DI through your employer, contractor, or another organization, privacy requests relating to Customer Data should ordinarily be directed first to that organization. Customer administrators may access, manage, correct, suspend, export, or delete account and operational information according to configured permissions, the customer agreement, and applicable law. We will assist the organization with verified requests as required by contract and applicable law.

1.3 Customer responsibilities for workforce and location data

Customers are responsible for providing legally required notices and obtaining any legally required consent, authorization, or other lawful basis before submitting personal information to Inventory DI, including employee or contractor information, signatures, photographs, and precise location information. Customers must configure and use the Services consistently with employment, labor, surveillance, privacy, notice, consent, and data-protection laws applicable to their workforce and jurisdictions.

2. Personal Information We May Collect

The categories of personal information we collect depend on your relationship with Inventory DI, the features used by your organization, device permissions, and applicable law. We may collect the following categories:

Account and contact information, such as name, business email address, business phone number, username, account credentials, organization, role, job title, and account preferences.

Organization and workforce information, such as company name, business unit, assigned role, coordinator or employee identifiers, job or project assignments, and information provided by a customer organization.

Operational and inventory information, such as warehouse, vehicle, Rolling Annex, jobsite, asset, product, inventory, issue, transfer, return, rotation, low-stock, custody, activity, and reporting records that may be associated with an identifiable user.

Location information. When a location-enabled workflow is used and permissions are granted, the Services may collect precise or approximate device location associated with an operational event, such as a transfer, verification, check-in/check-out, acceptance, issue, or other workflow record.

Signatures, photographs, attachments, and notes submitted through the Services. A handwritten signature image is treated as personal information; we do not use it as a biometric identifier unless separately disclosed and lawfully implemented.

Device, network, and usage information, such as IP address, browser type, operating system, device identifiers, app version, language, timestamps, crash information, log data, authentication events, and interactions with the Services.

Support and communications information, including emails, support tickets, feedback, demo requests, call notes, and other communications with us.

Business and billing information, such as billing contact information, invoices, transaction records, and business verification or tax information when needed for customer or vendor administration. If a third-party payment processor handles payment-card information, that processor’s privacy practices also apply.

Cookie and similar-technology information from our websites, subject to applicable consent requirements and our Cookie Policy.

3. Sources of Personal Information

We may obtain personal information:

directly from you when you create or use an account, contact us, request a demo, submit a form, upload information, or use a feature;

from a customer organization, employer, contractor, administrator, or authorized user who creates an account for you or assigns you to a job, vehicle, location, role, or workflow;

automatically from your browser, device, application, network connection, cookies, logs, and permitted location services;

from service providers that support hosting, security, communications, customer support, billing, analytics, authentication, or other business operations; and

from public or business sources where lawful and relevant to business-to-business operations.

4. How We Use Personal Information

We may process personal information for the following business and operational purposes:

to provide, operate, authenticate, maintain, support, and secure the Services;

to create and administer customer accounts, roles, permissions, company access, jobs, assets, locations, and authorized users;

to record and support inventory accountability, custody, issues, transfers, returns, rotation events, low-stock alerts, verification, and operational reporting;

to communicate with customers and users, provide support, respond to inquiries, schedule demonstrations, and deliver service-related notices;

to monitor reliability, diagnose errors, prevent abuse, investigate security events, and protect the confidentiality, integrity, and availability of the Services;

to improve usability, performance, features, documentation, and customer experience using data that is reasonably necessary for those purposes;

to manage billing, accounting, taxes, audits, legal obligations, corporate transactions, and enforcement of agreements;

to send business-to-business marketing communications where permitted by law, subject to applicable opt-out rights; and

for other purposes disclosed at the time of collection or authorized by you, the customer organization, or applicable law.

We do not use Customer Data for unrelated consumer advertising purposes, and we do not sell Customer Data as a data-broker business model.

5. Legal Bases for Processing in the EEA, United Kingdom, and Similar Jurisdictions

Where a legal basis is required, Inventory DI relies on one or more of the following, as applicable:

Performance of a contract or steps taken at your request before entering into a contract, including providing the Services and account administration.

Legitimate interests, including securing and improving the Services, supporting customers, preventing fraud or abuse, maintaining business operations, and communicating with business contacts, where those interests are not overridden by your rights and interests.

Compliance with legal obligations, including tax, accounting, security, regulatory, and lawful government requirements.

Consent, where required by law, including for certain cookies, marketing, precise location access, or other processing for which consent is the appropriate legal basis. You may withdraw consent as permitted by law without affecting processing that occurred before withdrawal.

When Inventory DI acts solely as a processor for Customer Data, the customer is responsible for identifying the appropriate legal basis for that processing, and Inventory DI processes the data on documented customer instructions.

6. Location Data and Mobile Device Permissions

Certain field workflows may use device location to create an operational record showing where a transaction or verification occurred. Depending on the device and feature, this may constitute precise geolocation data and may be treated as sensitive personal information under some laws.

Inventory DI does not intend to collect continuous background location merely because the app is installed. If a customer elects to enable a feature involving continuous or background location in the future, Inventory DI will provide additional disclosure and obtain or support any permissions required by applicable law and platform rules before that processing begins.

You may control device location permissions through your operating-system settings, but disabling a permission may prevent location-dependent features from functioning. Customer organizations remain responsible for workforce notices, policies, and legal requirements associated with employer-directed location use.

7. How We Disclose Personal Information

We may disclose personal information only as reasonably necessary for the purposes described in this Policy, including to:

the customer organization and authorized users within that organization, according to configured roles and permissions;

hosting, cloud infrastructure, security, authentication, communications, customer-support, analytics, billing, and other service providers that process information on our behalf under contractual obligations;

professional advisers such as attorneys, accountants, auditors, insurers, and consultants where reasonably necessary;

government authorities, regulators, law enforcement, courts, or other parties when required by law, legal process, or reasonably necessary to protect rights, safety, security, or the Services; and

a buyer, investor, lender, successor, or adviser in connection with a merger, financing, reorganization, sale of assets, acquisition, insolvency, or similar corporate transaction, subject to appropriate confidentiality and legal safeguards.

We require service providers and subprocessors to handle personal information consistently with applicable contractual and legal requirements appropriate to their role.

8. Sale, Targeted Advertising, and Sensitive Personal Information

As of the Effective Date, Inventory DI does not sell personal information for monetary consideration and does not share Customer Data for cross-context behavioral advertising. We do not use precise geolocation collected through operational workflows to infer sensitive characteristics or for unrelated advertising.

If our practices change in a way that constitutes a “sale,” “sharing,” targeted advertising, or another activity requiring an opt-out or consent under applicable law, we will update our disclosures and implement the required choice mechanisms before or when the changed processing begins.

9. Cookies and Similar Technologies

Our websites may use cookies and similar technologies for essential functionality, security, preferences, performance, analytics, and—if enabled—marketing. Where consent is legally required, non-essential technologies will be used only in accordance with the applicable consent choice. Additional details should be maintained in a separate Cookie Policy linked from the website footer.

Where applicable law requires recognition of a legally valid browser-based opt-out preference signal, such as Global Privacy Control, Inventory DI will honor the signal for the processing to which the law applies.

10. International Data Transfers

Inventory DI is intended to support customers operating in multiple jurisdictions. Personal information may therefore be processed in the United States and in other countries where Inventory DI, its customers, or authorized service providers operate. Those countries may have privacy laws that differ from the laws where you live.

Where required, we use recognized transfer mechanisms and safeguards appropriate to the jurisdiction and our role, which may include adequacy decisions, standard contractual clauses, the United Kingdom International Data Transfer Agreement or Addendum, contractual safeguards approved under Brazil’s LGPD, or other lawful transfer mechanisms. We will provide information about applicable safeguards upon request where required by law. Unless expressly agreed in a written customer agreement, Inventory DI does not guarantee that personal information or Customer Data will remain in a particular country or region.

Before global launch, Inventory DI should maintain a current subprocessor and international-transfer location list identifying relevant service providers and destination countries or regions where practicable and required by law.

11. Data Retention and Deletion

We retain personal information only for as long as reasonably necessary for the purposes described in this Policy, to provide the Services, to follow customer instructions, to satisfy contractual commitments, to comply with law, to maintain security and audit records, to resolve disputes, and to establish, exercise, or defend legal claims.

Customer Data is retained and deleted according to the applicable customer agreement, documented customer instructions, legal requirements, and our backup and disaster-recovery processes. Deletion from active systems may not immediately remove information from encrypted or restricted backups that are maintained for limited continuity, security, or legal purposes and are not used for ordinary business processing.

We may retain deidentified or aggregated information that cannot reasonably be linked to an identified or identifiable individual, subject to legal requirements applicable to deidentified data.

12. Data Security

Inventory DI maintains administrative, technical, and organizational safeguards designed to protect personal information against unauthorized access, acquisition, disclosure, alteration, loss, destruction, or misuse, taking into account the nature of the information, the Services, and reasonably foreseeable risks. We also use contractual controls with relevant service providers and limit access according to business need and authorization.

No information system, network, transmission method, or storage environment can be guaranteed to be completely secure. Accordingly, we do not promise absolute security. Users and customer organizations are also responsible for protecting credentials, devices, access permissions, and account configurations under their control.

13. Security Incidents and Data Breaches

We maintain processes for identifying, investigating, containing, documenting, and responding to suspected security incidents. If a security incident involving personal information triggers notification obligations under applicable law or contract, Inventory DI will provide required notices to the appropriate customer, regulator, authority, or affected individual within the timeframe applicable to our role and jurisdiction.

Nothing in this Policy is intended to waive mandatory privacy, security, breach-notification, or consumer rights. Any allocation of contractual risk, indemnity, limitation of liability, arbitration, governing law, or venue is addressed in the applicable Terms of Use, customer agreement, or Data Processing Addendum, subject to applicable law.

14. Your Privacy Rights

Depending on your location and our role, you may have some or all of the following rights regarding your personal information:

to confirm whether personal information about you is being processed and to access that information;

to correct inaccurate or incomplete personal information;

to request deletion or erasure, subject to legal and operational exceptions;

to obtain a portable copy of certain personal information where required;

to restrict or object to certain processing;

to withdraw consent where processing is based on consent;

to opt out of sale, sharing, targeted advertising, or certain profiling where applicable;

to limit certain uses or disclosures of sensitive personal information where applicable;

to appeal a decision we make on a privacy request where applicable; and

to lodge a complaint with a competent privacy or data-protection regulator.

We will not unlawfully discriminate or retaliate against you for exercising applicable privacy rights. We may take reasonable steps to verify your identity, authority, and the scope of a request before acting. We may deny or limit requests where permitted by law, including where we cannot verify the request, where an exception applies, or where the request would adversely affect the rights of another person.

If the information is Customer Data controlled by your employer or another Inventory DI customer, we may direct you to that customer so it can respond as the responsible controller/business. We will assist the customer as required by applicable law and contract.

15. How to Submit a Privacy Request or Appeal

To submit a privacy request, contact us using one of the methods below and identify the nature of your request. If applicable law gives you a right to appeal a denial, you may submit an appeal using the same contact information with the subject line “Privacy Appeal.”

Email: info@inventorydi.com

Phone: (800) 400-2801

Mail: 5818 Max Dr., Waterville, Ohio 43566

We will respond within the period required by applicable law. Timing may differ by jurisdiction, request type, verification requirements, extensions permitted by law, and whether Inventory DI is acting as a controller or processor.

16. United States State Privacy Rights

Residents of certain U.S. states may have rights that include access, correction, deletion, portability, opt-out of sale or targeted advertising, opt-out of certain profiling, limiting certain uses of sensitive data, authorized-agent rights, and an appeal process. We honor applicable rights based on the law that applies to the individual and processing activity.

Some state consumer privacy laws contain exemptions or different rules for employment-related or business-to-business information. Those exemptions do not eliminate rights that may exist under other privacy, employment, labor, surveillance, or sector-specific laws.

16.1 California Privacy Supplement

If the California Consumer Privacy Act, as amended (“CCPA”), applies to Inventory DI for a particular processing activity, California residents may have rights to know/access, delete, correct, opt out of sale or sharing, limit certain uses of sensitive personal information, use an authorized agent, and receive non-discriminatory treatment for exercising those rights.

Depending on the relationship and features used, Inventory DI may have collected the following CCPA categories during the preceding 12 months: identifiers; professional or employment-related information; commercial or business-account information; internet or other electronic network activity; geolocation data; visual, signature, and communications information; and sensitive personal information such as precise geolocation or account credentials. We use those categories for the purposes described in this Policy and may disclose them to service providers, customer organizations, professional advisers, transaction counterparties, or authorities as described above.

Inventory DI does not sell personal information for monetary consideration and does not share Customer Data for cross-context behavioral advertising as of the Effective Date. If a legally relevant sale or sharing practice is introduced, we will provide the disclosures and opt-out mechanisms required by law. Where legally applicable, we will honor Global Privacy Control signals for sale/sharing opt-out purposes.

16.2 Texas and Similar State Laws

Where the Texas Data Privacy and Security Act or a similar state privacy law applies, Inventory DI provides applicable rights to access, correct, delete, obtain a portable copy, opt out of covered targeted advertising/sale/profiling, and appeal certain request decisions. Sensitive data, including precise geolocation, is processed in accordance with applicable consent or other legal requirements. If an appeal is denied, we will provide any regulator-complaint information required by the applicable law.

17. EEA, United Kingdom, and Switzerland

Individuals in the European Economic Area, United Kingdom, or Switzerland may have rights to access, rectify, erase, restrict, object, receive data portability, withdraw consent, and lodge a complaint with a supervisory authority, subject to applicable conditions and exceptions. The legal bases we rely on are described in Section 5.

Where required because Inventory DI is not established in the relevant jurisdiction, representative information should be added here before offering Services that trigger a representative requirement:

EU Representative: N/A

UK Representative: N/A

Data Protection Officer: N/A

18. Brazil (LGPD)

Where Brazil’s Lei Geral de Proteção de Dados (LGPD) applies, data subjects may have rights including confirmation of processing, access, correction, anonymization/blocking/deletion in legally applicable circumstances, portability, information about sharing, revocation of consent where applicable, and petition to the Brazilian National Data Protection Authority (ANPD). Inventory DI will use lawful international-transfer mechanisms required by the LGPD and applicable ANPD regulations when those rules apply.

For processing in which a customer is the controller and Inventory DI is an operator/processor, the customer is generally responsible for responding to the data subject, and Inventory DI will provide assistance consistent with law and contract.

19. Canada, Australia, and Other Jurisdictions

Where Canadian privacy law applies, individuals may have rights of access, correction, transparency, and complaint, and organizations are expected to follow principles including accountability, identified purposes, consent where required, limiting collection, limiting use/disclosure/retention, safeguards, openness, and individual access.

Where Australian privacy law applies, Inventory DI will maintain an accessible privacy policy, handle personal information in accordance with applicable Australian Privacy Principles, and provide information about likely overseas disclosures as required. For global operations, destination countries or regions should be maintained in a current subprocessor/international-transfer notice where practicable.

Individuals in other jurisdictions may have additional or different rights under local law. Inventory DI will honor legally applicable rights and requirements even if they are not specifically listed in this Policy.

20. Automated Analytics and Decision-Making

The Services may use rules, analytics, alerts, prioritization, or artificial-intelligence-assisted functionality to identify operational patterns, summarize information, or recommend actions. These tools are intended to assist human users with inventory and operational decisions. Inventory DI does not design these features to make solely automated decisions about an individual that produce legal or similarly significant effects without human review, unless such processing is separately disclosed and lawfully implemented. Customer Data processed by AI-assisted functionality is used for authorized Service purposes and remains subject to the customer agreement, applicable data-processing terms, and the privacy and security controls described in this Policy.

21. Children’s Privacy

Inventory DI is a business and workplace service and is not directed to children. We do not knowingly collect personal information from children under 13 in the United States or from children below a higher minimum age where local law requires parental authorization for the relevant processing. If we learn that personal information was collected in violation of applicable children’s privacy law, we will take appropriate steps to delete or otherwise address the information.

22. Data Minimization and Sensitive Information

Customers and users should submit only information reasonably necessary for authorized business and operational purposes. Unless expressly required for an approved feature and lawful purpose, the Services are not intended for the collection of medical records, genetic data, government identification numbers, financial-account credentials, biometric templates used for identification, information about race or ethnicity, religion, sexual orientation, political affiliation, union membership, or other special-category information unrelated to inventory operations. Customers should not upload such information unless they have confirmed that it is necessary, authorized, and lawful.

23. Third-Party Services and Links

The Services may contain links to, integrate with, or rely on third-party products or services. This Policy does not govern a third party’s independent privacy practices when that third party acts for its own purposes. Review the applicable third-party privacy notices before providing information directly to those services.

24. Corporate Transactions

Personal information may be transferred as part of an actual or proposed merger, acquisition, financing, investment, reorganization, bankruptcy, sale of assets, or similar transaction, subject to applicable law and appropriate confidentiality or data-protection obligations. A successor that assumes the relevant business may continue to process information consistent with this Policy unless a different notice is provided as required by law.

25. Changes to This Privacy Policy

We may update this Policy to reflect changes in the Services, our practices, technology, vendors, law, or regulatory guidance. We will post the updated Policy with a revised “Last Updated” date and provide additional notice when legally required or when a change materially affects how personal information is processed. Where consent is legally required for a new purpose, we will obtain it before relying on that consent-based processing.

26. Contact Us

Questions, complaints, and privacy requests may be directed to the contacts below. We will review privacy complaints in good faith, investigate as appropriate, and respond within any period required by applicable law.

Inventory DI / Inventory DI, LLC

Email: info@inventorydi.com

Phone: (800) 400-2801

Mailing Address: 5818 Max Dr., Waterville, ohio 43566

If you are using Inventory DI through an employer or customer organization and your request concerns Customer Data controlled by that organization, please contact the organization first. We will cooperate with the organization as required by applicable law and contract.

27. Relationship to Customer Agreements and Terms

This Privacy Policy is a transparency notice describing privacy practices. It does not replace the customer agreement, Terms of Use, Data Processing Addendum, security commitments, or other written contract governing the Services. Where Inventory DI acts as a processor/service provider, the applicable customer agreement and Data Processing Addendum govern our processing instructions and contractual obligations. Nothing in this Policy is intended to waive a privacy right that cannot lawfully be waived.

KNOW WHAT YOU OWN.
KNOW WHERE IT IS.
KNOW WHO'S RESPONSIBLE.

© 2026 Inventory DI. All rights reserved.