CobraLedger logo CobraLedger 365 Backup & Archive

CobraLedger 365 Backup & Archive — Privacy Statement

Effective date: September 2, 2026

This Privacy Statement explains how Prevail-IT Solutions USA Inc, a Florida corporation located at 4491 S SR-7, Davie, FL 33314 ("Prevail-IT," "we," "us," or "our"), collects, uses, discloses, and protects personal data in connection with the CobraLedger 365 Backup & Archive service and the websites at cobraledger.com and mailarchiver.cobraledger.com (together, the "Service").

Because we serve customers worldwide, this Statement is designed to address the requirements of laws including the EU and UK General Data Protection Regulation ("GDPR") and U.S. state privacy laws such as the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA"). Where a specific law grants you rights, those rights apply to the extent that law applies to you.

1. Our two roles: controller and processor

Our role depends on the data:

This Statement primarily addresses data for which we are the controller. Our processing of Customer Data is governed by our agreement with the relevant customer, including our Terms and Conditions and, where applicable, a Data Processing Addendum ("DPA") available on request.

2. Personal data we collect

a. Account and contact data. When you register, subscribe, or communicate with us: your name, business email address, company name, role, and information you include in support requests.

b. Authentication data. Login is primarily through Microsoft sign-in (Microsoft Entra ID). We receive identity tokens and basic profile information from Microsoft to authenticate you. We do not receive or store your Microsoft password.

c. Billing data. Payments are processed by Square. We do not receive or store your full payment card number. We store only limited billing metadata and identifiers, such as card brand, the last four digits, expiration month/year, and Square customer, card, subscription, and invoice identifiers, together with subscription and payment status.

d. Customer Data (processed as processor). The email content, attachments, and mailbox metadata that the Service archives from your designated Microsoft 365 mailboxes, plus the searchable index and operational metadata we maintain to make it browsable. This may include personal data of senders, recipients, and individuals mentioned in email. We process this only to provide the Service, as described in Section 1.

e. Usage, device, and log data. Technical information generated when you use the Service, such as IP address, browser and device type, pages viewed, actions taken, timestamps, diagnostic and performance telemetry, and error logs. We use application performance monitoring within Microsoft Azure to collect this operational telemetry.

f. Cookies and analytics. The websites use cookies and similar technologies, including Google Analytics, to understand usage and improve the sites. See Section 11.

We do not intentionally collect special categories of personal data about our own account holders. Customer Data may, however, contain any information present in email; that content is controlled by our customer.

3. How we use personal data

We use personal data to:

We process Customer Data only to provide and support the Service and per our customer's instructions, and not for our own independent purposes. We may create and use aggregated or de-identified data that does not identify any individual to operate and improve the Service.

4. Legal bases for processing (GDPR and similar laws)

Where the GDPR or similar law applies and we are the controller, we rely on:

Where we act as processor for Customer Data, the customer (controller) is responsible for establishing the legal basis for the processing.

5. How we share personal data

We do not sell personal data, and we do not share it for cross-context behavioral advertising. We disclose personal data only as follows:

A current list of sub-processors is available to customers on request.

6. International data transfers

We are based in the United States, and our sub-processors may process data in the United States and other countries. When we transfer personal data from the European Economic Area, the United Kingdom, or Switzerland to a country that has not been recognized as providing adequate protection, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses and the UK Addendum, together with supplementary measures where appropriate. You may request more information using the contact details below.

7. Data retention

We retain personal data for as long as needed to provide the Service and for the purposes described in this Statement, and thereafter as required to comply with legal, tax, accounting, and audit obligations, resolve disputes, and enforce our agreements. Specifically:

8. Security

We implement technical and organizational measures designed to protect personal data, including per-customer database isolation, encryption in transit and at rest where supported, certificate-based application authentication to Microsoft services, read-only mail access, managed secret storage in a key vault, and access controls. No system can be guaranteed to be completely secure, and we cannot guarantee the absolute security of personal data. You are responsible for securing your own environment and credentials, including your Microsoft 365 tenant.

9. Your privacy rights

Depending on where you are and the applicable law, you may have rights to:

To exercise these rights with respect to data for which we are the controller, contact us at sales@prevail-it.com. We will respond within the time required by applicable law and may need to verify your identity. We will not discriminate against you for exercising your rights.

If your email was archived by an organization that uses the Service (for example, your employer), we process that Customer Data as a processor on that organization's behalf. Please direct requests regarding that data to the organization; if you contact us, we will refer your request to them and support their response as required.

10. U.S. state privacy rights (including California)

Where U.S. state privacy laws apply, you may have the rights described in Section 9, including the rights to know, access, correct, and delete personal information, and to be free from discrimination for exercising them. We do not sell personal information and do not share it for cross-context behavioral advertising, and we have not done so in the preceding twelve months. We do not knowingly process sensitive personal information about our account holders for purposes requiring an opt-out. To exercise your rights, contact us at sales@prevail-it.com. You may use an authorized agent where permitted, subject to verification.

11. Cookies and analytics

The websites use cookies and similar technologies that are strictly necessary for the sites to function, and, where permitted, analytics cookies through Google Analytics to help us understand how the sites are used and to improve them. Google Analytics may set cookies and collect information such as your IP address and usage activity; Google processes this data in accordance with its own policies. You can control cookies through your browser settings, and you can opt out of Google Analytics using Google's opt-out browser add-on. Where required by law, we request consent before setting non-essential cookies. We honor recognized browser-based opt-out preference signals where applicable law requires.

12. Children's privacy

The Service is intended for businesses and is not directed to children. We do not knowingly collect personal data directly from children under the age of 16. If you believe a child has provided us personal data in a controller capacity, contact us and we will take appropriate steps to delete it. Email archived on behalf of a customer is Customer Data controlled by that customer.

13. Data breach notification

If we become aware of a personal-data breach affecting data for which we are the controller, we will notify affected individuals and regulators where and as required by applicable law and without undue delay. Where we act as processor, we will notify the affected customer (controller) without undue delay as required by our agreement so that the customer can meet its notification obligations.

14. Third-party links and services

The Service integrates with and may link to third-party services, including Microsoft and Square. Their processing of personal data is governed by their own privacy policies, and we are not responsible for their practices. We encourage you to review their policies.

15. Changes to this Privacy Statement

We may update this Privacy Statement from time to time. If we make material changes, we will post the updated Statement with a new effective date and, where appropriate, provide additional notice. Your continued use of the Service after the effective date constitutes acceptance of the updated Statement.

16. Contact us

For questions about this Privacy Statement or to exercise your rights, contact:

Prevail-IT Solutions USA Inc 4491 S SR-7, Davie, FL 33314, United States Email: sales@prevail-it.com

© 2026 Prevail-IT Solutions USA Inc. All rights reserved.