Last updated: July 28, 2026
Embrava USA, Inc. and, where applicable, its affiliates and subsidiaries, including Embrava Pty Ltd and other Embrava group entities, respect your privacy and are committed to protecting personal data in accordance with this Privacy Policy.
In this Privacy Policy, "Embrava", "Company", "we", "our" or "us" means the Embrava entity responsible for the relevant website, product, service or interaction. The relevant Embrava entity may depend on your location, the website or service you use, and the nature of your relationship with us.
This Privacy Policy describes how we collect, use, retain, disclose and protect personal data when you access or use our websites, products, applications, devices, platforms, support channels, communications and other services that link to this Privacy Policy.
This Privacy Policy applies only to information we collect:
It does not apply to information collected by:
Please read this policy carefully to understand our policies and practices regarding your information and how we treat it. By interacting with our Services or providing us with your information, you agree to the collection, use, and sharing of your information as described in this privacy policy. This policy may change from time to time (see How We Retain Your Personal Data). Your continued use of the Services after we make changes as described here is deemed to be acceptance of those changes, so please check the policy periodically for updates.
"Personal data" is information that identifies, relates to, or describes, directly or indirectly, you as an individual, such as your name, email address, telephone number, home address, or payment information.
The types and categories of personal data we collect or process include:
For Users who access and license Embrava Connect, we collect the User's first name, last name, email addresses and time zone.
If you are a California resident, to access our supplemental California privacy statement, visit www.embrava.com/california-privacy-notice.
If we combine or connect non-personal statistical or technical data with personal data so that it directly or indirectly identifies an individual, we treat the combined information as personal information.
We collect information about you when you interact with our Services, such as when you create or update an account, or make a purchase, create a reservation or request.
As you navigate through and interact with our Services, we may use automatic data collection technologies to collect information that may include personal data. Information collected automatically may include usage details, IP addresses, operating system, and browser type, and information collected through cookies, web beacons.
Using automatic collection technologies helps us to improve our Services and to deliver a better and more personalized experience.
The technologies we use for this automatic data collection may include:
To the extent any of these automated technologies are considered a personal data, sale, targeted advertising, or profiling, under applicable laws, depending on where you live, you may opt out from use of these automated technologies for such uses by emailing [email protected]. Please note that some Services features may be unavailable as a result.
We use information that we collect about you or that you provide to us, including any personal data, to:
The usage information we collect, whether connected to your personal data or not, helps us improve our Services and deliver a better and more personalized experience by enabling us to:
We may disclose aggregated information about our users, and information that does not identify any individual, without restriction.
We may also disclose personal data that we collect or you provide as described in this privacy policy:
This section describes mechanisms you can use to control certain uses and disclosures of your information and rights you may have under state law, depending on where you live.
You can set your browser to refuse all or some browser cookies or other tracking technology files, or to alert you when these files are being sent. If you disable or refuse cookies or similar tracking files, some Services features may be inaccessible or may not function properly. Some browsers include a "Do Not Track" (DNT) setting that can send a signal to the online services you visit indicating you do not wish to be tracked.
Depending on your state of residency, you may have certain rights related to your personal data, including:
Important: The exact scope of these rights vary by state. There are also several exceptions where we may not have an obligation to fulfill your request.
To exercise any of these rights or appeal a decision regarding a consumer rights request, please email us at [email protected].
If you are a California resident, additional information applies to you. To access our supplemental California privacy statement and learn more about California residents' privacy rights, visit www.embrava.com/california-privacy-notice.
We use commercially reasonable administrative, physical, and technical measures designed to protect your personal data from accidental loss or destruction and from unauthorized access, use, alteration, and disclosure. Sensitive and private data exchange between the Site and its Users happens over a SSL secured communication channel and is encrypted and protected with digital signatures.
However, no website, mobile application, system, electronic storage, or online service is completely secure, and we cannot guarantee the security of your personal data transmitted to, through, using, or in connection with the Services. In particular, email, texts, and chats sent to or from the Services may not be secure, and you should carefully decide what information you send to us via such communications channels. Any transmission of personal data is at your own risk.
The safety and security of your information also depends on you. You are responsible for taking steps to protect your personal data against unauthorized use, disclosure, and access.
We retain data as long as there is a legitimate business need, or to meet regulatory or contractual requirements. Once data is no longer needed, it must be securely disposed of or archived.
Personally identifiable information is deleted or de-identified as soon as it no longer has a business use. If you are a California resident, visit www.embrava.com/california-privacy-notice for more information about the retention periods that apply to the personal data categories we collect.
Specific retention periods for certain categories of data are maintained in our internal data retention schedule. For example, customer operational personal data associated with Embrava Connect Cloud is generally deleted within 90 days following termination of the applicable customer relationship, unless a longer retention period is required by law, contract, security requirements, dispute resolution, fraud prevention, or other legitimate business purposes.
Subject to applicable law and our legitimate business, legal, security, and compliance obligations, individuals may request deletion of their personal data by contacting us at [email protected]. We may take reasonable steps to verify the identity of the requestor before processing a deletion request. Following verification, we will review the request and delete, anonymize, or otherwise process the personal data in accordance with applicable law and our data retention practices. Where deletion is not possible due to legal, regulatory, contractual, security, fraud prevention, or other legitimate business requirements, we will retain the information only for as long as necessary for those purposes.
We may retain information that is subject to a legal hold, litigation preservation requirement, regulatory investigation, audit requirement, or other legal obligation notwithstanding a deletion request.
Upon request, we may provide confirmation that a deletion request has been completed, subject to applicable legal and security requirements.
Where permitted by applicable law or agreement, we may identify our customers by company name and display their company logo in our marketing materials, customer lists, case studies, presentations, website, and other promotional materials for the purpose of identifying organizations that use our products and services. We do not disclose personal information of individual users for this purpose. Customers who wish to opt out of such use may contact us at [email protected].
We may share personal data with service providers, contractors and subprocessors that perform services on our behalf, including cloud hosting providers, infrastructure providers, payment processors, customer support providers, analytics providers, communication service providers, professional advisors and other vendors that assist us in operating our business and delivering the Services. Such parties are authorized to access personal data only as necessary to perform services for us and are required to protect such information through appropriate contractual and security obligations.
Your personal data may be transferred to, processed in, or accessed from countries other than the country in which you reside. Where required by applicable law, we implement appropriate safeguards designed to protect personal data transferred across international borders. These safeguards may include standard contractual clauses, the UK international data transfer addendum or agreement, adequacy mechanisms, or other lawful transfer mechanisms.
We may use automated tools and technologies, including artificial intelligence and machine learning technologies, to support, maintain, improve and secure our products and services. Unless expressly authorized by a customer or otherwise permitted under applicable law and contractual commitments, we do not use customer personal data submitted through our products and services to train publicly available or general-purpose artificial intelligence models. Where artificial intelligence or automated processing is used in connection with our Services, we implement reasonable measures designed to promote security, reliability and compliance with applicable law.
This section applies where the EU General Data Protection Regulation, the UK General Data Protection Regulation, the UK Data Protection Act 2018, or other applicable European data protection laws apply to our processing of your personal data.
For website visitors, business contacts, prospects, and individuals who interact directly with Embrava for sales, support, billing, account administration, security, or similar business purposes, Embrava acts as a controller of the personal data it collects and uses for those purposes. Where Embrava processes personal data on behalf of an enterprise customer or another organization, Embrava may act as a processor, and we process such personal data in accordance with that customer's instructions and applicable contractual terms. The customer is responsible for providing any required privacy notices to its own users, employees, contractors, or representatives.
Data Protection Officer. Based on the nature, scope and purpose of Embrava's processing activities, Embrava has assessed that it is not required to appoint a Data Protection Officer under Article 37 of the GDPR/UK GDPR. Individuals may nonetheless direct privacy inquiries to [email protected].
We process the personal data described in this policy on the following legal bases: performance of a contract with you or your organization, or steps taken at your request before entering into a contract; compliance with a legal obligation; and our legitimate interests, provided that your data protection rights and freedoms do not override these. Our legitimate interests include operating, securing, and improving our Services; managing our customer and business relationships; understanding and improving how our Services are used; preventing fraud, misuse, and security incidents; and protecting our legal rights and the rights, safety, and property of our users, customers, and others. Where required by law, we rely on your consent, such as for certain marketing communications or the use of non-essential cookies.
Whether the provision of personal data is required, and we ask you to provide personal data to comply with a legal requirement, or under a contract with you or your organization, and you do not provide it, we may be unable to provide the relevant product, service, or feature, or to enter into or perform the contract. Where the provision of personal data is optional, we will indicate this at the point of collection.
Source of personal data. Some personal data described in this policy is collected directly from you. Depending on your interaction with Embrava, personal data may also be provided to us by an enterprise customer, its administrators or authorized users, or generated by connected systems or integrations configured by a customer, rather than collected directly from you. We may also obtain personal data, such as business contact details, from third-party data providers and publicly available sources.
If you are located in the European Economic Area or the United Kingdom, subject to applicable law, you may have the right to:
You may exercise these rights by contacting us at [email protected]. If you are in the European Economic Area, you may lodge a complaint with your local data protection authority. If you are in the United Kingdom, you may lodge a complaint with the UK Information Commissioner's Office. We encourage you to contact us first so that we can try to resolve your concern. Where your request relates to personal data we process on behalf of an enterprise customer, we may refer your request to that customer or ask you to contact the customer directly, and we will assist the customer where required by applicable law and contractual terms.
Our Services are not intended for, and we do not knowingly collect any personal data from, children under the age of 18. If we learn we have collected or received personal data from a child under 18 years old without verification of parental consent, we will delete that information.
We may update this policy from time to time, and we will provide notice of any such changes to the policy as required by law. The date the privacy policy was last updated is identified at the top of the page. We will notify you of changes to this policy by updating the "last updated" date and posting the updated policy on the Services. We may email or otherwise communicate reminders about this policy, but you should check our Services periodically to see the current policy and any changes we have made to it.
To exercise your rights or ask questions or comment about this privacy policy or our privacy practices, contact us at:
Embrava USA, Inc.
31 Hudson Yards, Level 11, New York, NY 10001
[email protected]
To register a complaint or concern, please email us at [email protected].