VD

Data Protection & Your Rights

Everything we do to safeguard your workspace data — plus your legal rights under U.S. state and federal privacy law. Written in plain English, no legalese pretending to be friendly.

Last updated: July 6, 2026 Vitae Dux v3.2 Plain-English Guide

What's in this guide

  1. Our Security & Privacy Commitments — what we built to protect you
  2. Your Rights as a Vitae Dux User — what you can do, anytime
  3. U.S. State Privacy Laws — the 19 comprehensive laws by 2026
  4. U.S. Federal Laws — FTC Act, COPPA, GLBA, HIPAA scope
  5. International Users — our U.S.-only scope
  6. How to Exercise Your Rights — concrete steps
  7. Mutual Protections — how the law protects you and us
  8. Contact & Questions

1. Our Security & Privacy Commitments

Vitae Dux is a leadership accountability tool. Your workspace contains tasks, projects, goals, comments — sometimes sensitive operational and people-related data. We treat it accordingly. Here are the concrete technical controls we've built, not promises:

🔒 Defense-in-depth architecture

📂 Data portability — your data is yours

🛡 What we never do

🔐 Hosting & encryption

2. Your Rights as a Vitae Dux User

Regardless of which U.S. state you live in, these rights apply to you:

📥 Right to Access

You can download a complete copy of your data anytime via About → Data → Download backup. No request needed, no review window, no fee.

✏️ Right to Correction

You can edit any field of any record at any time directly in the app. We do not maintain frozen "official" copies that you'd need to ask us to amend.

🗑 Right to Deletion

From About → Data, you can wipe your workspace data ("Reset workspace") or delete your account entirely ("Delete account"). Account deletion is immediate — a synchronous server-side hard-delete of your workspace and account (organization, memberships, restore points, and profile), and your active sessions are revoked. Before the delete runs, the app automatically generates a full export and emails it to you, and it blocks the deletion if that backup cannot be saved. (Separately, encrypted operational backups may persist up to 30 days before they rotate out.) For fraud-prevention, legal, tax, and audit purposes we retain a minimal record of the deletion itself — the account email, the account holder's name, the workspace name, the role, and the date it was deleted — and payment records (invoices) are retained by our payment processor as required by law. We do not retain your workspace content.

📤 Right to Portability

Your exported JSON is structured, machine-readable, and re-importable into any account. No proprietary lock-in.

🚫 Right to Opt Out of Sale or Sharing

Not applicable in the negative sense — we do not sell, share, or transfer your workspace data to third parties for advertising, profiling, or any purpose other than delivering the service you signed up for.

📜 Right to Know Categories We Collect

We collect: your email (for sign-in), the workspace content you create (tasks, projects, goals, comments, blockers, time blocks), your interaction patterns (which features you use, how often), and technical info (browser, IP at the edge for security only). See the Privacy Policy for the exhaustive list.

🛑 Right to Non-Discrimination

Exercising any of the rights above will never trigger account restriction, price changes, or feature downgrades. You exercise your rights → we comply. Nothing changes about your service.

3. U.S. State Privacy Laws

By May 2026, 19 U.S. states have comprehensive consumer-data-privacy laws in force or coming into force. We've built Vitae Dux to honor the union of these protections — meaning even if your state hasn't passed a law yet, you get the same rights as a Californian.

The pragmatic truth:

Rather than tier rights state by state, we apply the strongest common floor to every user. This is the same approach taken by most reputable SaaS — it's simpler, fairer, and avoids the "if you live in California you matter more" optics.

California

CCPA / CPRA

The California Consumer Privacy Act, expanded by the California Privacy Rights Act (effective Jan 2023). The foundational U.S. state privacy law. Grants rights to access, delete, correct, opt-out of sale/sharing, and limit use of sensitive personal information.

Enforced by: California Privacy Protection Agency (CPPA) + AG

Virginia

VCDPA

The Virginia Consumer Data Protection Act (Jan 2023). First state law after CCPA. Mirrors most CCPA rights with a notable opt-IN for sensitive categories.

Enforced by: Virginia Attorney General

Colorado

CPA

The Colorado Privacy Act (July 2023). Universal opt-out signal (Global Privacy Control) recognized.

Enforced by: Colorado Attorney General

Connecticut

CTDPA

Connecticut Data Privacy Act (July 2023). Strong opt-in for sensitive data, broad consumer rights.

Enforced by: Connecticut Attorney General

Utah

UCPA

Utah Consumer Privacy Act (Dec 2023). Slightly narrower than VCDPA — opt-out only model, higher business-size threshold.

Enforced by: Utah Attorney General

Texas

TDPSA

Texas Data Privacy and Security Act (July 2024). Applies regardless of business size if you target Texas residents.

Enforced by: Texas Attorney General

Oregon

OCPA

Oregon Consumer Privacy Act (July 2024). Extended deletion rights — must propagate to processors.

Enforced by: Oregon Attorney General

Montana

MTCDPA

Montana Consumer Data Privacy Act (Oct 2024). Smallest-state model — low population threshold.

Enforced by: Montana Attorney General

Delaware

DPDPA

Delaware Personal Data Privacy Act (Jan 2025). Mirrors Connecticut closely.

Enforced by: Delaware Department of Justice

Iowa

ICDPA

Iowa Consumer Data Protection Act (Jan 2025). Lighter-touch — opt-out only, no profiling rights.

Enforced by: Iowa Attorney General

New Hampshire

NHDPA

New Hampshire Data Privacy Act (Jan 2025). Strong rights including profiling opt-out.

Enforced by: NH Department of Justice

New Jersey

NJDPA

New Jersey Data Privacy Act (Jan 2025). Notable: applies to financial information beyond GLBA scope.

Enforced by: NJ Attorney General + Division of Consumer Affairs

Tennessee

TIPA

Tennessee Information Protection Act (July 2025). Includes a safe-harbor for businesses with documented privacy programs aligned with NIST.

Enforced by: Tennessee Attorney General

Minnesota

MCDPA

Minnesota Consumer Data Privacy Act (July 2025). Strong rights to question and contest profiling decisions.

Enforced by: Minnesota Attorney General

Maryland

MODPA

Maryland Online Data Privacy Act (Oct 2025). Notably restrictive on selling and sharing sensitive personal data.

Enforced by: Maryland Attorney General

Indiana

INCDPA

Indiana Consumer Data Protection Act (Jan 2026). Aligned with Virginia model.

Enforced by: Indiana Attorney General

Kentucky

KCDPA

Kentucky Consumer Data Protection Act (Jan 2026). Virginia-style framework.

Enforced by: Kentucky Attorney General

Rhode Island

RIDTPPA

Rhode Island Data Transparency and Privacy Protection Act (Jan 2026). Adds transparency requirements for data brokers.

Enforced by: Rhode Island Attorney General

Florida

FDBR

Florida Digital Bill of Rights (July 2024). Narrower scope ($1B+ revenue threshold) but includes specific protections for minors and biometric data.

Enforced by: Florida Department of Legal Affairs

Illinois — separate but critical

Illinois doesn't have a general consumer privacy statute, but it has two laws that significantly affect SaaS:

4. U.S. Federal Laws

FTC Act, Section 5

The Federal Trade Commission can pursue companies that engage in "unfair or deceptive" data practices, regardless of which state the consumer lives in. This is the primary federal enforcement tool against bad privacy actors. We take care that every privacy claim in our Privacy Policy, terms, and this guide is accurate — because misrepresenting our practices would create FTC exposure for us and harm for you.

HIPAA

HIPAA does not apply to Vitae Dux. We are not a healthcare provider, insurance plan, or business associate of one. Do not enter Protected Health Information (PHI) into Vitae Dux — we have no HIPAA-compliant data handling, no Business Associate Agreement (BAA) capability, and no breach-notification path for HIPAA-covered data.

COPPA — Children's Online Privacy

Vitae Dux is a B2B leadership tool intended for adult workplace use. We do not knowingly collect data from anyone under 13. If you believe a minor has signed up, contact [email protected] and we will delete the account immediately.

GLBA — Financial Privacy

The Gramm-Leach-Bliley Act covers financial institutions and their service providers. Vitae Dux is neither, so GLBA's specific safeguards do not govern our service. However, we voluntarily apply the safeguards that would be required under GLBA — encryption in transit (HTTPS/TLS), encryption at rest through our database provider, access controls, audit logging — because they are best practices regardless of whether they are legally required.

FERPA — Educational Records

FERPA applies to educational institutions receiving federal funding. If your organization plans to enter student-identifiable records into Vitae Dux, we should sign a Data Processing Agreement first — contact [email protected] before doing so.

Stored Communications Act (SCA)

Under the SCA, your stored data on our service is legally protected against disclosure to anyone (including law enforcement) without a court order or warrant. We do not voluntarily disclose customer data to government agencies. Subpoenas and warrants are reviewed by counsel and, where legally permitted, we notify you before any disclosure.

5. International Users

The Service is intended for businesses located in the United States. We do not currently offer it to, or target, individuals or organizations in the European Union, United Kingdom, or European Economic Area, and we do not rely on the EU-U.S. Data Privacy Framework or Standard Contractual Clauses at this time.

We do not represent that Vitae Dux complies with the EU or UK General Data Protection Regulation (GDPR / UK GDPR), Canada's PIPEDA, Brazil's LGPD, or other non-U.S. data-protection laws. If we expand into those markets in the future, we will update this guide and our Privacy Policy before doing so.

Our infrastructure runs primarily in U.S. data centers. If you access the Service from outside the United States, you do so on your own initiative and consent to your information being transferred to and processed in the United States, whose data-protection laws may differ from those of your home jurisdiction. The access, correction, export, and deletion controls described in Section 2 are available to every user regardless of location.

6. How to Exercise Your Rights

The fastest path is always the in-app controls. For anything those don't cover, email us.

What you wantHow to do itHow long it takes
📥 Get a copy of my data About → Data → 📥 Download backup (.json) Instant
✏️ Correct something Edit the field directly in the app Instant
🧹 Wipe my workspace, keep account About → Data → Reset workspace (type RESET) ~5 seconds
🗑 Delete my account entirely About → Data → Delete account (type DELETE) ~10 seconds
📜 Know exactly what we collect Read Privacy Policy, Section 2 5 min read
📨 Data subject request (formal) Email [email protected] with "Data Subject Request" subject Within 30 days (45 if complex)
🚨 Report a privacy concern Email [email protected] with "Privacy Concern" Within 24 hours acknowledgment

Verification — why we ask

For formal data subject requests submitted by email, we may ask you to confirm details that prove account ownership (last sign-in date, organization name, etc.). This is to protect you from someone impersonating you to extract your data. We do not retain those verification details after the request is fulfilled.

7. Mutual Protections — How the Law Works for Both of Us

Privacy law isn't just about restricting us. It also defines the rules we both rely on. Here's the honest two-sided view:

How these laws protect you:

How these laws protect us:

Where the law protects us together:

8. Contact & Questions

If anything in this guide is unclear, contradicts what you see in the app, or you have a specific situation we haven't covered:

For binding legal terms, see: