Privacy Policy
Effective date: September 4, 2026
Last updated September 4, 2026
HQDIRECTOR CORP (“HQDirector,” “we,” “us,” or “our”) describes in this policy how information may be handled across HQDirector.com, MyHQDirector, and Director applications. The information involved and our role differ by surface.
Roles and scope
HQDIRECTOR CORP is responsible for operating its public website, MyHQDirector account and commercial services, and the Director applications. For customer and operational data entered into a Director application, HQDirector may process that data for the customer and under the customer's instructions, including as described in the applicable Data Processing Addendum. The applicable agreements and actual service configuration determine the parties' responsibilities for that processing.
HQDirector.com visitor and contact data
The public website may process visitor technical information, such as IP address, browser and device information, requested pages, referral information, timestamps, and security or abuse signals. If you use the Contact workflow, it may process the details you provide, including your name, company, business contact information, selected department or product interest, subject, and message.
MyHQDirector account and commercial data
MyHQDirector may process identities, authentication and session information, organizations, memberships, roles, subscriptions, invoices, entitlements, assignments, and application-launch activity. We use this information to provide account access, administer organizations and subscriptions, determine available entitlements, launch authorized applications, operate the service, and protect it from misuse.
Director application customer and operational data
Director applications may process customer data and operational data that an authorized customer or its users provide or generate while using the applications. The categories, visibility, and uses of that data depend on the application and the customer's configuration and instructions.
Payments, taxes, and logs
Stripe is the intended payment processor for checkout and related Stripe Billing and Stripe Tax functions. Complete payment-card data is handled by Stripe and is not stored by HQDirector. HQDirector may process payment, subscription, invoice, entitlement, and tax-related records needed to administer the commercial relationship. We also may process security and audit logs to operate, secure, investigate, and troubleshoot the services.
Providers
Applicable provider roles may include Replit infrastructure; Clerk identity and session services; Stripe, including Stripe Billing and Stripe Tax; Cloudflare security and delivery; Upstash Redis abuse and security state; Resend contact transmission when the workflow accepts messages; an authorized Microsoft 365 mailbox; and CSS or system font dependencies. Providers may process information as needed for their applicable services and configurations.
Choices and requests
Subject to applicable law, you may request access, correction, deletion, export, withdrawal of consent, or information about applicable sale, sharing, or targeted-advertising choices. Submit a request through the Privacy request form. An acknowledgment confirms intake only. We may need additional information to verify your identity, authority, and the request before acting; acknowledgment does not mean verification or completion.
Retention
We retain information only for as long as reasonably needed for the applicable website, account, commercial, product, security, support, or legal purpose. The applicable service, customer instructions, provider configuration, and legal requirements determine the period. We do not represent that every provider or data category uses one universal retention period.
Changes
We may update this policy as the services, providers, or applicable requirements change. The updated policy will show its effective date and last-updated date.