Definitions
The following terms are used throughout this Privacy Policy:
- "Client" means any company or organization that has subscribed to the Suri platform under a services agreement with us.
- "Client Employee" means any individual employed by or working for a Client whose data may be processed through Suri in connection with the Client's use of our Services.
- "Controller" means the entity that determines the purposes and means of processing personal data. Our Clients are the data controllers with respect to their employees' personal data.
- "Processor" means the entity that processes personal data on behalf of a controller. Suri acts as a data processor with respect to Client Employee data.
- "Personal Data" means any information that identifies or could reasonably identify an individual person.
- "Sensitive HR Data" means personal data relating to employment status, compensation, performance, disciplinary actions, medical or family leave, accommodation requests, or other employment-related sensitive information.
- "Platform" means the Suri AI HR Business Partner software embedded in Slack, Microsoft Teams, or other integrations.
Scope of This Policy
This Privacy Policy applies to:
- Visitors to our website at surgepeoplepartners.com and any Suri-branded landing pages.
- Prospective clients who submit inquiries, schedule demos, or apply for early access.
- Clients who have contracted with us to use the Suri platform.
- Client Employees who interact with Suri through Slack, Microsoft Teams, or other integrated tools.
This policy does NOT apply to the internal HR or employment practices of Surge People Partners, Inc. as an employer. Employee privacy matters are addressed separately in our internal HR policies.
Information We Collect
3.1 Information You Provide to Us
When you visit our website, request a demo, or contact us, we may collect:
- Name, email address, phone number, and job title
- Company name, company size, and industry
- Information submitted through contact forms, scheduling tools, or early access applications
- Communications and correspondence you send to us
3.2 Information Clients Provide During Onboarding
When a Client onboards onto the Suri platform, we receive and process:
- Company policies, employee handbooks, HR process documents, and related materials uploaded to configure the Suri platform
- Organizational information including company structure, locations, and applicable state employment laws
- Integration credentials for Slack, Microsoft Teams, or other authorized platforms
- Billing and payment information processed through our third-party payment processors
3.3 Information Generated Through Platform Use
When Client Employees interact with the Suri platform through Slack or Microsoft Teams, we may process:
- Questions and inquiries submitted to Suri regarding HR policies, compliance, leave, performance management, onboarding, and related topics
- Responses, guidance, and documents generated by the Suri platform in response to user interactions
- Metadata associated with interactions, including timestamps, channel identifiers, and session information
- Performance conversation coaching interactions between managers and Suri
- Leave and accommodation inquiries, including family and medical leave requests
- Onboarding-related questions and responses
We may also process sensitive HR data through the platform, including but not limited to information relating to medical conditions, family status, compensation, and disciplinary matters. This data is processed solely in connection with providing the HR guidance services requested by the Client.
3.4 Automatically Collected Information
- IP address and general geographic location
- Browser type, operating system, and device information
- Pages visited, time spent on pages, and referral sources
- Cookies and similar tracking technologies (see Section 7)
How We Use Information
4.1 To Provide Our Services
- Responding to HR-related questions from Client Employees through the Suri platform
- Generating HR guidance, compliance alerts, document templates, and coaching support
- Configuring the Suri platform with Client-specific policies and organizational context
- Facilitating human escalation when situations require human HR judgment
- Monitoring platform performance and resolving technical issues
4.2 Artificial Intelligence and Automated Processing
Suri uses artificial intelligence to process information and generate HR guidance. Specifically:
- Your interactions with Suri are processed by our AI systems to generate context-specific HR responses grounded in your company's policies, applicable employment law, and SHRM/HRCI best practices.
- The Suri platform uses automated logic to detect when situations require human escalation, such as matters involving terminations, harassment allegations, or legal exposure. In those cases, interactions are routed to a qualified HR professional.
- Suri does not make binding employment decisions. All guidance is advisory in nature. Final employment decisions remain with the Client and its authorized personnel.
- We do not use Client Employee interactions to train general-purpose AI models. Each Client's data is isolated within their dedicated environment.
If you are located in a jurisdiction that requires disclosure of automated decision-making, you have the right to request human review of any automated output that has a significant effect on you. Please contact your employer's HR representative or contact us directly using the information in Section 14.
4.3 Communications and Marketing
- Respond to inquiries and provide requested information about our Services
- Send information about Suri's features, updates, and pricing
- Send marketing communications (you may opt out at any time)
- Administer our early access program and related communications
4.4 Legal and Compliance Purposes
- Comply with applicable laws, regulations, and legal obligations
- Respond to lawful requests from courts, government authorities, or law enforcement
- Enforce our Terms of Service and contractual obligations
- Protect the rights, property, or safety of Suri, our clients, or others
Data Controller and Processor Roles
5.1 Suri as Data Processor
With respect to personal data belonging to Client Employees, Suri acts as a data processor. Our Clients are the data controllers who determine the purposes and means of processing their employees' HR data. We process that data on the Client's behalf and pursuant to their instructions, as governed by our Data Processing Agreement (DPA).
If you are a Client Employee with questions about how your personal data is used, please first contact your employer. Your employer is responsible for its own privacy practices and obligations to you as an employee.
5.2 Suri as Data Controller
With respect to information we collect directly from website visitors, prospective clients, and our own platform usage data, Suri acts as a data controller and is responsible for compliance with applicable privacy laws governing that data.
5.3 Client Obligations
- Providing appropriate notices to their employees about the use of Suri as an HR tool
- Obtaining any required consents from employees for AI-assisted HR processing
- Ensuring their use of Suri complies with applicable employment and data privacy laws in their jurisdiction
- Entering into a Data Processing Agreement with Suri if required by applicable law
Sharing and Disclosure of Information
We do not sell personal data. We do not rent or trade personal data for marketing purposes. We may share information in the following limited circumstances:
6.1 Service Providers
- Cloud hosting and infrastructure providers
- AI and machine learning infrastructure providers
- CRM and customer communication tools
- Payment processors and billing platforms
- Analytics and product telemetry tools
- Email marketing and communication platforms
- Security and fraud prevention services
6.2 Escalation to HR Professionals
A core feature of the Suri platform is human escalation. When the platform determines that a situation requires human HR judgment, interactions may be escalated to a qualified HR professional employed by or contracted with Surge People Partners. These professionals are bound by confidentiality obligations and process information solely to provide the requested HR guidance.
6.3 Legal Requirements
We may disclose information when we believe in good faith that disclosure is required by applicable law, regulation, court order, or lawful governmental process. Where legally permitted, we will notify affected parties prior to disclosure.
6.4 Business Transfers
In the event of a merger, acquisition, reorganization, or sale of assets, personal data may be transferred as part of that transaction. We will provide notice prior to any such transfer and require the acquiring entity to honor the terms of this Privacy Policy or provide equivalent protection.
6.5 Protection of Rights
We may disclose information as necessary to enforce our Terms of Service, protect the rights or property of Suri or our clients, investigate fraud or security incidents, or protect against legal liability.
Cookies and Tracking Technologies
7.1 Types of Cookies We Use
- Essential Cookies: Required for basic website functionality. These cannot be disabled without affecting core site features.
- Analytics Cookies: Help us understand how visitors interact with our website. Data is aggregated and anonymized.
- Marketing Cookies: Used to deliver relevant content and measure advertising campaign effectiveness. We use tools such as Google Ads and LinkedIn conversion tracking.
- Preference Cookies: Remember your settings and preferences to improve your experience on return visits.
7.2 Managing Cookies
You can control or disable cookies through your browser settings. Note that disabling certain cookies may affect the functionality of our website. We also honor browser-level Do Not Track (DNT) signals where technically feasible.
7.3 Third-Party Analytics
We use third-party analytics services including Google Analytics. Data collected is governed by the respective providers' privacy policies.
Data Retention
- Website visitor data and inquiry information: Retained for up to 24 months following last contact.
- Client account and configuration data: Retained for the duration of the client relationship and for up to 36 months following termination of services.
- Client Employee interaction data: Retained as specified in the applicable Data Processing Agreement, typically for the duration of the client relationship plus a 12-month wind-down period.
- Billing and financial records: Retained for 7 years as required by applicable law.
- Anonymized and aggregated analytics data: May be retained indefinitely as it does not identify individuals.
Upon termination of a Client relationship, we will, at the Client's election, return or securely delete Client Employee personal data within the timeframe specified in the Data Processing Agreement, unless retention is required by law.
Data Security
9.1 Technical Safeguards
- Logical multi-tenancy architecture ensuring each Client's data is isolated and inaccessible to other Clients
- Encryption of data in transit using TLS 1.2 or higher
- Encryption of sensitive data at rest
- Access controls and role-based permissions limiting data access to authorized personnel
- Regular security assessments and vulnerability testing
- Secure software development lifecycle practices
9.2 Organizational Safeguards
- Employee confidentiality agreements and data protection training
- Vendor security assessments for third-party service providers
- Incident response and breach notification procedures
- Regular review and update of security policies
9.3 Limitations
No data transmission over the internet and no method of data storage can be guaranteed to be 100% secure. In the event of a data breach affecting your personal data, we will notify affected parties as required by applicable law.
U.S. State Privacy Rights
10.1 California (CCPA / CPRA)
If you are a California resident, the CCPA as amended by the CPRA provides the following rights:
- Right to Know: Request disclosure of categories and specific pieces of personal information we have collected about you.
- Right to Delete: Request deletion of personal information we have collected about you, subject to certain exceptions.
- Right to Correct: Request correction of inaccurate personal information we hold about you.
- Right to Opt Out: We do not sell or share personal information for cross-context behavioral advertising purposes.
- Right to Limit Sensitive Data Use: We use sensitive personal information only as necessary to provide our services.
- Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.
California residents may submit requests within 45 days by contacting us at the information provided in Section 14.
10.2 Other U.S. States
Residents of Colorado, Connecticut, Virginia, Texas, Montana, Oregon, and other states with comprehensive privacy laws may have similar rights. We honor these rights to the extent required by applicable law. Contact us using the information in Section 14 to exercise your rights.
10.3 HR Data Exemptions
Many U.S. state privacy laws include exemptions for personal data processed in the employment context. If you are a Client Employee, please consult your employer's HR department for information about your employment-related privacy rights.
International Users
Our Services are operated from the United States and are primarily intended for U.S.-based companies. If you access our Services from outside the United States, your information may be transferred to, stored, and processed in the United States, where data protection laws may differ from those in your country.
For clients and individuals located in the EEA, United Kingdom, or Switzerland, please contact us to discuss appropriate data transfer mechanisms prior to using the Suri platform.
Children's Privacy
Our Services are not directed to individuals under the age of 16. We do not knowingly collect personal data from children under 16. If you believe we have inadvertently collected information from a child under 16, please contact us immediately and we will promptly delete such information.
Third-Party Links and Integrations
Our website and platform may contain links to third-party websites and integrate with third-party platforms including Slack and Microsoft Teams. This Privacy Policy does not apply to those third-party platforms. We encourage you to review their privacy policies:
- Slack Technologies, Inc. — slack.com/privacy-policy
- Microsoft Corporation — privacy.microsoft.com
- Any scheduling, payment, or other tools linked from our website
Your Rights and How to Exercise Them
Regardless of your location, you may contact us to request access, correction, or deletion of your personal data, opt out of marketing communications, or ask questions about our privacy practices. We will respond within 30 days.
Privacy Contact
Surge People Partners, Inc. / SHP Nexus, Inc.
490 Post St, Suite 500 #1028
San Francisco, CA 94102
Email: [email protected]
Updates to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will:
- Post the updated policy on our website with a revised "Last Updated" date
- Notify active Clients via email or in-platform notification at least 30 days before material changes take effect
- For changes required by law, we may provide shorter notice where necessary
Your continued use of our Services after the effective date of any update constitutes your acceptance of the revised Privacy Policy.