Privacy Policy
This website privacy policy (“Privacy Policy”) applies to XedaLink, LLC, its respective owners, operators, and employees (“XedaLink”, “we”, “us”, or “our”) and describes how we collect, use, disclose, and protect personal information, and outlines your rights under applicable U.S. state and federal privacy laws.
This Privacy Policy applies to all current or former User information collected by or provided to us. This Privacy Policy also applies to the following websites owned and operated by XedaLink, as well as any other websites or online services where this Privacy Policy is posted (“Sites”):
- XedaLink.com
XedaLink is the controller of data provided to, collected by, or processed in connection with your use of our Sites (“User”). Using the Sites constitutes your User acceptance and agreement to the terms contained in this Privacy Policy. If you do not agree with the terms set forth in this Privacy Policy, please discontinue using the Sites immediately.
This Privacy Policy does not apply to third-party websites, and we do not accept responsibility for your use of any third-party websites, even if we provide a link on the Sites to such third-party websites. We encourage you to review the privacy policies of any third party prior to disclosing information to that party.
The purpose of this Privacy Policy is to notify Users of the following: what information we collect, why we collect User data, how we use it and disclose it with third parties, how we store and protect it, and the choices you have regarding our collection, use, and disclosure of this information.
1. Applicability and Legal Exemptions
We operate as a specialized business-to-business (“B2B”) web-based order fulfillment hub that streamlines credit and verification data ordering from application to closing and offers technology platforms exclusively to consumer reporting agencies, credit clients, wholesale lenders and other regulated entities who are engaged in activities governed by the Fair Credit Reporting Act (FCRA) and the Gramm-Leach-Bliley Act (GLBA). Our services enable these B2B clients to use our platform to securely process, transmit, and manage their consumer reporting, verification, identity, real property, and similar data in compliance with their legal and regulatory obligations. XedaLink is not a consumer reporting agency, and we do not offer our technology platforms directly to individual consumers or to the downstream customers of our clients. We do not determine the purposes for which personal data is collected or used by our clients or their downstream customers. Instead, we act solely as a service provider only to our B2B clients, acting on behalf of and under the direction of those B2B clients in support of their FCRA and GLBA regulated operations.
Accordingly, and consistent with applicable law, including Cal Civ. Code § 1798.145 and equivalent provisions in other state privacy laws, this notice does not apply to:
- Personal information processed by our clients or their downstream customers in accordance with the FCRA.
- Data processed by our clients or their downstream customers in accordance with the GLBA.
- Publicly available information, such as government real property records.
These exemptions apply to the majority of the data processed by our clients through our B2B platforms, and we are not the provider of such data. If we process limited categories of personal data outside of our role as a service provider or outside of these regulated contexts, such as information collected from our public website, job applicants, or business contacts, those practices are addressed separately in the relevant sections of this Privacy Policy.
2. Information we Collect for Business or Commercial Purposes
For activities not covered by exemptions, we may collect:
- Identifiers – Name, business contact info, IP address, User device information
- Professional/Employment Information – Job title, company
- Internet/Network Activity – Portal access logs
- Commercial Info – Transaction records
- Geolocation – Approximate region
3. Sources of Information we Collect for Business or Commercial Purposes
We may collect information from the following categories:
- Directly from you
- Advertising networks
- Internet service providers
- Data analytics providers
- Government entities
- Operating systems and platforms
- Social networks
- Data brokers
4. Online Information we Collect for Business or Commercial Purposes
Our Sites may use tracking technologies (such as cookies, scripts/pixels, web beacons, and device identifiers) to collect limited technical information about Users’ interactions with our websites. This may include IP address, browser type, operating system, Internet Service Provider (ISP), date and time of visit, firmographic information, and clickstream data.
We use this information solely to:
- Operate and improve the performance of our Sites,
- Measure and analyze traffic and usage patterns,
- Identify the company associated with a Site visitor to provide us with B2B company-level (firmographic) insights, and
- Tailor content and communications related to our own products and services.
We work with trusted third-party service providers and other restricted vendors to support these functions, including platforms such as Google Analytics, Google Ads, Fullstory, and Zoominfo. These providers are bound by written agreements that limit their use of personal information to services performed solely on our behalf. They are prohibited from using this information for their own purposes, including cross-context behavioral advertising. We may use these tools to deliver ads to you about our own products and services, but only in a context that does not involve selling or sharing your personal information under applicable U.S. state privacy laws.
We do not sell or share personal information collected via cookies or online tracking technologies, and we do not allow third parties to use such data to advertise products or services of other companies.
You can manage cookie preferences through your browser settings or via opt-out tools provided by our vendors. To opt out of interest-based advertising or data collection by our analytics vendors, you may visit:
- Google Ads Settings – Manage how Google uses your info for personalized ads
- Google Analytics Opt-Out – Prevent Google Analytics from collecting data
- Fullstory Opt-Out – Disable Fullstory session tracking
- Zoominfo Opt-Out – Request removal of information from Zoominfo
- Digital Advertising Alliance (DAA) – Opt out of interest-based advertising from participating companies
- Network Advertising Initiative (NAI) – Opt out of targeted advertising by NAI members
5.Business or Commercial Purpose of Information we Collect
We use information to:
- Deliver services and information under contract
- Comply with legal and regulatory obligations
- Prevent fraud, misuse, or security threats
- Operate and audit our websites and internal systems
- Marketing and Advertising as described in Section 6 below
We may also use User’s personal information to perform services on behalf of the business, including maintaining or servicing accounts, providing customer service, processing or fulfilling orders and transactions, verifying customer information, processing payments, providing financing, providing analytic services, providing storage, or providing similar services on behalf of the business.
6. Marketing and Advertising to Businesses
We may use information we collect to deliver advertising and marketing communications and other information regarding our products, service and promotions or to administer promotions or to deliver newsletters, receipt messages, e-mails, mobile messages and special offers, including:
- Short-term, transient use, including, but not limited to, non-personalized advertising shown as part of a User’s current interaction with us, provided that the User’s personal information is not disclosed to another third party and is not used to build a profile about the User or otherwise alter the User’s experience outside the current interaction with us; or
- Providing advertising and marketing services, except for cross-context behavioral advertising, to a User.
If at any time the User would like to unsubscribe from receiving future emails, detailed unsubscribe instructions can be found at the bottom of each email, or the User may contact us at:
Email: [email protected]
Attention Name: Legal Department
Mailing Address: 370 Reed Road, Suite 100, Broomall, Pennsylvania 19008
Telephone Number: 800-350-7787
7. Collection of Personal Information – Past 12 Months
The Notice at Collection Table below applies solely to non-exempt disclosures and solely as those disclosures are made by us in our capacity as the controller.
THIRD PARTIES
- Data Vendors or Service Provider
- Operating/CRM/Workflow Platforms
- XedaLink Affiliate Companies
- Security Tools
- Data Analytics Providers (Restricted)
- Marketing Vendors (XedaLink Services)
- Professional Social Network Sites
- Government Entities
Internet/Network Activity
Yes – Internal Commercial Use
- Security Tools
- Data Analytics Providers (Restricted)
- Internet Service Providers
- Marketing Vendors (XedaLink Services)
Geolocation Region
Yes – Internal Commercial Use
- Operating/CRM/Workflow Platforms
- Data Analytics Providers (Restricted)
- Security Tools
- Internet Service Providers
B2B Client Applicant Personal Info
(principal)
Yes – Internal Commercial Use
- Data Vendors or Service Providers
- Workflow Systems
- XedaLink Affiliate Companies
- Security Tools
XedaLink Job Applicant Personal Info
(not otherwise exempt)
Yes – Internal Commercial Use
- Service Providers
- XedaLink Affiliate Companies
- Security Tools
- Government Entities
XedaLink Employee or Contractor Personal Info (not otherwise exempt)
Yes – Internal Commercial Use
- Service Providers
- HR/Payroll Platforms
- XedaLink Affiliate Companies
- Government Entities
8. Do Not Track and Universal Opt-Out Disclosures
We do not knowingly sell or share personal information as defined under applicable U.S. state privacy laws. Because we do not engage in these activities, our website does not respond to browser “Do Not Track” signals or universal opt-out mechanisms such as Global Privacy Control (GPC). If we become aware that personal information has been sold or shared in violation of our policy, we will take prompt steps to remediate the situation.
9. Sensitive Personal Information and Consent
We do not use or disclose sensitive personal information about you except for purposes specified under California Consumer Privacy Act (Cal Civ. Code § 1798.100 et seq) (“CCPA”) and equivalent provisions in other state privacy laws.
We do not process sensitive personal information for purposes requiring opt-in consent under U.S. state privacy laws. We have no actual knowledge that we have sold any personal information of any consumer under 16 years of age.
10. Children’s Privacy
Our Sites are not intended or designed to be used by persons under the age of eighteen (18). We do not collect personal information from any person that we know to be under the age of thirteen (13). Guardians of minor children, however, may contact us if you believe your child has provided us with personal information without your consent.
11. Consumer Rights and Choices
For data not covered by exemptions, you may have the right to:
- Know/Access your personal information
- Correct inaccuracies to your personal information
- Delete your personal information
- Limit the use and disclosure of your sensitive personal information
- Port your personal information
- Appeal any denial of a request of any of these rights
- Equal Treatment without discrimination for making such a request or appeal
If you are a resident of California, you may visit this website to learn more about these rights under the CCPA: CA Attorney General CCPA FAQ
12. Submitting a Request
If your information has been requested by or processed on behalf of one of our clients we are a “service provider” and if you wish to exercise any rights you may have about this type of information, please note that the respective client or their downstream customer is deemed the “controller” under applicable U.S. state privacy laws, responsible for the information concerned, and you should make your request to the applicable client or their downstream customer directly.
If XedaLink is the controller, not acting as a service provider:
Email: [email protected]
Attention Name: Privacy Department
Mailing Address: XedaLink, LLC, 370 Reed Road, Suite 100, Broomall, Pennsylvania 19008
Telephone Number: 800-350-7787
Reasonable verification will be required. We may require you to provide certain personal information to process and/or verify your request, including your name or email address, so we can match that information against our business records to authenticate your identity. Only you, or someone legally authorized to act on your behalf, may make a verifiable consumer request related to your personal information. To authorize an agent, provide written authorization signed by you and your designated agent and send it to us.
13. Appeals
To exercise your right to appeal a denial of a privacy rights request, contact us using the same method. We will respond as required by law.
14. Data Retention
We retain data for as long as you use our services or as necessary to fulfill the purpose(s) for which it was collected, provide our services, resolve disputes, establish legal defenses, conduct audits, pursue legitimate business purposes, enforce our agreements, and comply with applicable laws.
15. Security measures
We implement reasonable administrative, technical, and physical safeguards to protect personal information from unauthorized use, access, alteration, destruction, or disclosure.
16. Updates to This Policy
We may revise this Privacy Policy from time to time. Unless otherwise stated, any modifications to this Privacy Policy will go into immediate effect after they have been posted, as indicated by the Effective Date above. You are responsible for checking this Privacy Policy when you visit our Sites to review the current Privacy Policy. If you do not agree with the current Privacy Policy at the time of your use, you should cease use of the Sites immediately
We review and update this Privacy Policy at least once every 12 months, or as required by changes in the law or our business practices.
17. Notice to EU Data Subjects
We do not offer services to or monitor individuals located in the European Union.
18. Accessibility of This Privacy Policy
We are committed to ensuring that our privacy policy and related notices are accessible to all individuals, including those with disabilities. If you require this notice or any related information in an alternative format, please contact us and we will make reasonable efforts to provide the requested information in a format that meets your needs.
To receive this notice in an alternative format please contact:
Email: [email protected]
Attention Name: Legal Department
Mailing Address: XedaLink, LLC, 370 Reed Road, Suite 100, Broomall, Pennsylvania 19008
Telephone Number: 800-350-7787
19. Artificial Intelligence; Automated Decision Making
The tools we use on our Sites, including analytics and advertising tools, may incorporate artificial intelligence or machine learning functionality that does not result in automated decision making that produces legal or similarly significant effects on individuals.
Our clients may have access to automated decision tools within our SaaS, including tools that may incorporate artificial intelligence or machine learning functionality. Clients or their respective downstream customers are solely responsible for their utilization of such tools. Their purpose is exclusively to support human decision-making, and they are not intended to replace human decision-making for decisions that produce legal or similarly significant effects on individuals.
20. Questions about this Policy
To contact us for more information about this Privacy Policy:
Email: [email protected]
Attention Name: Legal Department
Mailing Address: 370 Reed Road, Suite 100, Broomall, Pennsylvania 19008
Telephone Number: 800-350-7787
