This Notice explains how Cerebrum City collects, uses, discloses, and retains information in connection with the Product. It applies when you: (a) install or use iQBus in your Microsoft Azure tenant or subscription (a "Customer Deployment"); (b) purchase subscriptions or services from us; (c) contact us for sales or support relating to the Product; or (d) are a business contact at an organization we research or approach about the Product, as described in Section 3.4.
It does not apply to data stored or processed inside a Customer Deployment, which remains under the customer's exclusive control as described in Section 2.
Information collected when you visit our websites is addressed in our separate website privacy policy.
Customer Deployments. The Product is deployed into the customer's own Azure tenant or subscription. All business data, message payloads, and integration content in a Customer Deployment are stored and processed in the customer's environment, on Azure resources the customer owns and pays for, under the customer's own Microsoft agreements. For that data, the customer (or its own customers) is the data controller, and Cerebrum City is neither a controller nor a processor.
Publisher management access. The Product is delivered as an Azure Managed Application. As a structural property of that delivery model, Cerebrum City's publisher identity, a group in Cerebrum City's Microsoft Entra tenant, holds the Owner role over the managed resource group created by the deployment, scoped to that resource group and not extending to other resources in the customer's subscription. That role is fixed for the life of the Marketplace plan and cannot be narrowed after publication. That authorization exists to protect Cerebrum City's intellectual property in the deployed software, to support the deployment, and to deliver in-place upgrades where the edition provides them. It does not carry a route to data in the Customer Deployment: storage shared key access is disabled, the database servers accept Microsoft Entra authentication only, every data service is reachable only through a private endpoint with public network access disabled, and Cerebrum City holds no application identity in the Product. Obtaining such a route would require a modification to the deployed infrastructure, including deployment of code to the Product's application services, which executes as the Product's managed identity within the deployment's virtual network. That capability is inherent to the delivery model and cannot be removed without also removing our ability to deliver updates. All management operations performed by Cerebrum City principals against those resources are recorded in the customer's own Azure activity log, which we cannot alter, and the customer may end the authorization at any time by deleting the managed application. The customer may further constrain the managed resource group through Azure Policy at subscription scope; we cannot remove such a policy assignment, and any exemption created within the managed resource group is recorded in the customer's activity log. We do not deploy code to, or otherwise modify, a Customer Deployment other than to deliver an update or patch under the Product Agreement or to perform work the customer has requested in writing. Multi-factor authentication is enforced for every member of the publisher identity group, and we will notify affected customers without undue delay on confirming a compromise of that identity or of the systems we use to deploy code to Customer Deployments.
Cerebrum City as controller. We act as an independent data controller for: subscription administration and licensing; Registration Data described in Section 3.1; and sales, billing, and support administration.
Cerebrum City as processor. If a customer engages us for production support or professional services and, in the course of that engagement, grants us access to its environment or provides materials containing personal data, we act as a data processor for that activity only, limited to what is necessary to perform the services and governed by the applicable services agreement and statement of work and any data processing terms agreed in that engagement.
3.1 Registration Data. To activate a Customer Deployment, the registering user completes a one-time Registration inside the Product and requests a License Key. When the Registration is submitted, the Product transmits the following to us, once:
First name, last name — The registering user. Purpose: Issuing the License Key, contact about the license.
Organization — The customer organization operating the deployment. Purpose: License administration.
Business email address — Where the License Key is sent. Purpose: Issuing the License Key, contact about the license and the Product.
Edition — Starter, Grow, or Enterprise. Purpose: License administration.
Agreement acceptance — Your acceptance of the Product Agreement and the version accepted. Purpose: Evidence of the terms on which the License Key was issued.
Starter Edition declarations — For the Starter Edition only: the declaration that the deployment will not process regulated data, and the acknowledgement of the Starter Edition terms, as described in the Product Agreement. Purpose: Evidence of the terms on which the License Key was issued.
Product version — The installed version. Purpose: License administration, support.
We record the time of receipt. We then issue a License Key to the registered email address, normally within two business days. This Registration is the only information the Product transmits to us, and it is transmitted only when you submit it. The Product Agreement and this Notice are displayed at Registration by loading their published text from www.iqbus.io into your browser; that request is made by your browser, retrieves a plain text file, and carries no information about your deployment. The Product does not contact Cerebrum City at any other time. It does not transmit telemetry, usage data, message payloads, business content, configuration, user activity, logs, error traces, or health information.
No remote diagnostics. The Product performs its own health checks and notifies the customer within the Customer Deployment. The Product contains no remote diagnostic capability, and we do not collect logs or data from a Customer Deployment through the Product. Any access by Cerebrum City personnel to a Customer Deployment occurs only under a statement of work, on the customer's express grant, is recorded in the customer's Azure activity log, and is never to an environment containing regulated data of the kinds described in Section 11.
3.2 Business Contact and Account Data. When you purchase, evaluate, or inquire about the Product or our services, we collect business contact information (name, work email address, phone number, employer, role), order and contract details, and billing information necessary to administer subscriptions and services.
We also receive business contact information from Microsoft. The Product is acquired through the Microsoft commercial marketplace, and Microsoft provides us with the details of customers who request contact or complete a purchase. The fields Microsoft provides are first name, last name, email address, phone number, country, company, and job title, where those are available. We use them to administer the subscription and to respond to the inquiry.
3.3 Support and Professional Services Data. If you purchase support or professional services, we may process support tickets, communications, and attachments or log exports you choose to provide, and any temporary access credentials you grant. You must not include protected health information, payment card data, government-issued identifiers, financial account numbers or credentials, personal information about individuals, or other regulated or sensitive personal data in tickets, logs, diagnostics, or other materials provided to us, as described in Section 11, and you are responsible for redacting such data before sharing.
3.4 Information from Third-Party Sources. We obtain business contact information and company information from commercial data providers and from publicly available sources, including company websites, professional and business directories, and public technology and hiring data. The categories we obtain are business contact details (name, job title, work email address, work telephone number, employer) and organization-level information about a company's size, industry, locations, and technology environment.
We use this information for sales research, to identify organizations whose environment suggests the Product may be relevant to them, and to make direct business-to-business contact about the Product. It is held in our internal customer relationship management system. We do not obtain or use information from these sources about individuals in a personal capacity, and we do not sell it or share it for advertising.
If you receive contact from us and do not wish to, tell us and we will stop and remove your details. You may also exercise the rights described in Section 12, including asking what we hold about you and where we obtained it.
For customers in jurisdictions that require a legal basis for processing (such as the EEA and the UK, when we offer the Product there), the corresponding legal bases are listed.
Issue License Keys and administer licenses — Data used: Registration Data (Section 3.1). Legal basis: Contract performance. Retention: Life of the license plus 7 years.
Administer subscriptions — Data used: Account data (Section 3.2). Legal basis: Contract performance. Retention: Term plus 90 days.
Billing, accounting, tax compliance — Data used: Billing and contract data. Legal basis: Contract performance; legal obligation. Retention: 7 years.
Provide support and services — Data used: Support data (Section 3.3). Legal basis: Contract performance. Retention: Term plus 90 days, or as the SOW requires.
Respond to inquiries; sales follow-up — Data used: Business contact data (Section 3.2). Legal basis: Legitimate interests. Retention: 24 months after last interaction.
Sales research and business-to-business outreach — Data used: Business contact and company data from third-party sources (Section 3.4). Legal basis: Legitimate interests. Retention: 24 months after collection or last interaction, whichever is later.
Security, fraud prevention, enforcing agreements — Data used: All categories as necessary. Legal basis: Legitimate interests; legal obligation. Retention: As needed for the purpose.
Product improvement using aggregated data — Data used: Aggregated, de-identified data (Section 5). Legal basis: Legitimate interests. Retention: Indefinite (not personal data).
We may create and use aggregated or de-identified data (including statistics derived from Registration Data) to operate, analyze, improve, and develop our products and services, to protect the security and integrity of our services, and to produce statistical analyses, provided that such data does not identify any customer or natural person. We commit to maintaining such data in de-identified form and not attempting re-identification.
We do not sell personal information and we do not share personal information for cross-context behavioral advertising. We may disclose information: to Microsoft, in connection with the Microsoft commercial marketplace, through which the Product is acquired. Customers purchase from and pay Microsoft, and Microsoft remits payment to us; Microsoft is the transacting party for those purchases and its handling of the transaction and of payment details is governed by the customer's own agreements with Microsoft, not by this Notice. We do not receive or process payment card details. Microsoft also provides the Azure services that host our registration and licensing systems and the Microsoft 365 services we use for email and business operations, and our customer relationship management system is operated internally rather than by a third party; to comply with law, regulation, or legal process; to protect rights, safety, and the security and integrity of our services, and to prevent fraud; and in connection with a corporate transaction (merger, acquisition, financing, or asset sale), consistent with applicable law and subject to confidentiality obligations.
We retain Registration Data, License Key records, and related subscription records for the life of the license and for 7 years after it ends, because those records evidence the terms on which the license was issued. For a Starter Edition license, which has no fixed term, the period runs from the later of the last Registration and the last contact from the customer. Other subscription records are retained until 90 days after contract expiration or termination, unless a longer period is required by law or necessary to resolve disputes or enforce agreements. Support records follow the same rule unless the applicable statement of work provides otherwise. Billing and contract records are retained as required by tax and accounting law. When retention periods expire, we delete or de-identify the data.
Data inside a Customer Deployment is governed by the customer's own configuration, not by this Notice. The Product's tracking retention window and the deletion of an Application are described in the Product documentation.
We use administrative, technical, and organizational safeguards appropriate to the nature of the data we store, including access controls, encryption in transit for Registration submissions, and encryption at rest for Registration Data and license records.
Customer Deployments are controlled by the customer, and their security posture depends on customer configuration. All editions authenticate to the deployment's data services using a managed identity; no local database accounts or issued passwords are used. Cerebrum City's access to a Customer Deployment is limited as described in Section 2.
If we confirm a security incident affecting personal data we hold about you or your organization, we will notify affected customers without undue delay, consistent with applicable law, our contractual commitments, and the legitimate needs of law enforcement and incident remediation. Contractual notification timelines for regulated customers are addressed in the applicable services agreement or data processing addendum.
Cerebrum City does not disable, suspend, or alter Customer Deployments remotely. The Product contains no licensing mechanism by which we can disable it, and we do not use the publisher management access described in Section 2 to interrupt a Customer Deployment for non-payment or for any other licensing reason. Where a Paid Edition is acquired through the Microsoft Azure Marketplace, Microsoft bills and collects the subscription fees, and the consequences of non-payment are governed by the customer's agreements with Microsoft. We may suspend the issuance of License Keys, or the systems that receive Registrations, where necessary to address a security threat or to comply with law; such a suspension does not affect Customer Deployments already activated.
The Product runs entirely within the customer's Azure environment. In connection with the Product and with product support, Cerebrum City does not create, receive, maintain, or transmit protected health information ("PHI") on behalf of customers. Message payloads and tracking data reside on Azure resources in the customer's own subscription, under the customer's Microsoft agreements, and Cerebrum City has no route to that data as described in Section 2. Accordingly, in that capacity Cerebrum City is not a business associate under HIPAA and does not enter into business associate agreements. Product support is delivered without access to a customer environment containing PHI, and Cerebrum City will not accept such access under the Product Agreement. A customer whose policy requires a business associate agreement from any vendor holding administrative rights over systems that host PHI should evaluate the Paid Editions with that understood; professional services engagements can carry one, as described below.
Professional services are different. Where a customer separately engages Cerebrum City for professional services and that engagement requires access to an environment containing PHI, or the viewing of PHI in the course of the work, that engagement is governed by the applicable services agreement and statement of work, and Cerebrum City will enter into a business associate agreement where one is required by law. Customers in regulated industries remain responsible for their own compliance within their environments.
The Starter Edition is not licensed for regulated data. It must not be used to process, transmit, or store protected health information, payment card data, government-issued identifiers, financial account numbers or credentials giving access to financial accounts, personal information about individuals, meaning any data that identifies a natural person or is linked to one, or any other data that a law, regulation, or contract requires to be protected with specific technical safeguards, in production or in testing. Starter Edition Registration requires a declaration to that effect, which we rely on in issuing the License Key and do not verify. Workloads involving such data require the Grow or Enterprise Edition. The Product Agreement states the terms and the limits of liability that apply.
Do not send us PHI, payment card data, government-issued identifiers, financial account numbers or credentials, personal information about individuals, or other regulated or sensitive personal data in support tickets, log files, diagnostics, or any other materials; redact such data before sharing anything with us. Materials received in violation of this Section will be deleted, and any costs of handling them may be charged to the customer, as provided in the Product Agreement.
Depending on your state of residence, you may have rights to access, correct, delete, or obtain a portable copy of personal information, and to appeal a refusal. We extend these request rights to all US residents regardless of whether a specific state statute applies to us. Because we do not sell or share personal information and do not process personal information for targeted advertising or profiling with significant effects, no opt-out of those activities is required; if that changes, we will update this Notice and provide the required opt-out mechanisms.
To exercise rights, contact privacy@cerebrumcity.com. We will verify your request using the contact information associated with our records and respond within the time required by applicable law (and in any event within 45 days). Authorized agents may submit requests with proof of authorization. We will not discriminate against you for exercising rights. For data held inside a Customer Deployment, direct requests to the customer that operates the deployment, as that customer is the controller of that data.
The Product is offered through the Microsoft commercial marketplace in the markets Microsoft makes available, which include the European Economic Area and the United Kingdom. The following applies to personal data of persons in those regions and in other regions with comprehensive data protection laws: our legal bases for processing are listed in Section 4; you have the rights of access, rectification, erasure, restriction, portability, and objection, and the right to lodge a complaint with your supervisory authority; where we transfer personal data to the United States, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum or IDTA, as applicable) as the primary transfer mechanism; and where Article 27 of the GDPR or its UK equivalent requires us to appoint a representative, we will identify that representative here. We respond to data subject requests within one month.
The Product and our services are intended for business use and are not directed to children under 16. We do not knowingly collect personal information from children.
We may update this Notice from time to time. Updates become effective on the posted Effective Date. If we make material changes, we will provide notice reasonably in advance, such as by email to subscription contacts or by prominent notice on the page where this Notice is published.
Cerebrum City Corporation, 730 Peachtree St NE, Atlanta, GA 30308. privacy@cerebrumcity.com.