Privacy Policy.

One policy, worldwide — written to the GDPR standard and applied to everyone, wherever you are.

Our approach: rather than maintaining different policies per country, we apply the strictest standard — the EU General Data Protection Regulation — to every visitor, globally. If your local law grants you a right, you have it; if GDPR grants more, you get that instead.

1. Who we are — the controller

Etch is built by Procloud Labs, 4444 2nd Ave, Detroit, MI 48201, United States ("we," "us"). We are the data controller for personal data collected on this site. Contact: info@procloudlabs.com (privacy requests get priority handling). We have not appointed a Data Protection Officer, as our processing does not meet the Article 37 thresholds; this contact route reaches the people accountable for privacy directly.

2. What we collect, why, and on what legal basis

  • Early-access signups — your email address. Purpose: sending the early-access communications you asked for. Legal basis: consent (Art. 6(1)(a)) — withdrawable at any time via the unsubscribe link in every email or by writing to us.
  • Contact-sales requests — name, work email, company, team size or Salesforce footprint, product interest, and your message. Purpose: responding to the conversation you requested. Legal basis: steps taken at your request prior to entering a contract (Art. 6(1)(b)).
  • Server logs — IP address, browser type, pages visited, timestamps. Purpose: keeping the site available, secure, and understanding in aggregate what content matters. Legal basis: our legitimate interest (Art. 6(1)(f)) in operating a secure website — an interest we've assessed as minimally intrusive because logs are short-lived, never enriched, and never used for profiling.

That's the complete list. No accounts, no ad-network pixels, no data brokers, no special-category data, and no automated decision-making or profiling that produces legal or similarly significant effects (Art. 22).

3. What we don't do

We do not sell or rent personal data. We do not share it for cross-context behavioral advertising. We do not use it to train models. VIP-list addresses receive email about Etch — nothing else.

4. Cookies

Essential cookies only, where needed for the site to function — these require no consent under the ePrivacy rules. If we ever add optional analytics, they will be off by default, load only after affirmative consent, and declining will change nothing about how the site works. We honor Global Privacy Control signals as an opt-out where applicable law gives them effect.

5. Recipients and processors

Personal data is shared only with processors acting on our documented instructions under Article 28 agreements: our hosting provider, our email delivery provider, and — once the product launches — Stripe for payment processing. Each may use the data solely to provide its service to us. We disclose data to authorities only where the law genuinely compels it, and we'll notify you unless legally barred from doing so.

6. International transfers

We are a US company, so data you submit is processed in the United States. For visitors in the EEA, UK, and Switzerland, transfers are protected by the European Commission's Standard Contractual Clauses (and the UK Addendum / Swiss equivalent) with our processors, alongside the technical measures in §9. Where a provider is certified under the EU–US Data Privacy Framework, we rely on that adequacy decision as well. You can request a copy of the relevant safeguards at the contact address above.

7. Retention — specific periods

  • VIP-list emails: until you unsubscribe or request deletion; removed within 30 days of either.
  • Sales inquiries: 24 months from last contact, then deleted unless a contract conversation is active.
  • Server logs: rotated and deleted within 90 days; security-incident extracts kept only as long as the investigation requires.

When the product launches, customer workspace data will be governed by a separate data processing agreement — the audit-grade permanence Etch promises applies to campaign records inside the product, at the customer's direction, never to this website's visitor data.

8. Your rights — GDPR standard, applied globally

Whoever and wherever you are, you can exercise all of the following by emailing info@procloudlabs.com:

  • Access — a copy of the personal data we hold about you (Art. 15).
  • Rectification — correction of inaccurate data (Art. 16).
  • Erasure — deletion, the "right to be forgotten" (Art. 17).
  • Restriction — pausing processing while a dispute is resolved (Art. 18).
  • Portability — your data in a structured, machine-readable format (Art. 20).
  • Objection — to processing based on legitimate interest (Art. 21).
  • Withdraw consent — at any time, without affecting prior processing (Art. 7(3)).

We respond within one month, free of charge, and we verify identity proportionately (usually by replying from the email on file). We will never discriminate against you — in price, service, or otherwise — for exercising any right. If you're in the EEA or UK, you also have the right to lodge a complaint with your supervisory authority (the data protection authority in your member state, or the UK ICO) — though we'd appreciate the chance to resolve it directly first.

9. Security

Data in transit is encrypted with TLS; data at rest is encrypted by our hosting provider; access is restricted to the people who need it, with logged administrative access. If a breach ever creates risk to you, we'll notify the relevant authority within 72 hours and affected individuals without undue delay, as Articles 33–34 require.

10. Children

This site is not directed at children under 16, and we don't knowingly collect their data. If you believe a child has provided us information, contact us and we'll delete it.

11. Regional disclosures

California (CCPA/CPRA): we do not "sell" or "share" personal information as those terms are defined, and we collect only the categories listed in §2 for the purposes stated. The rights in §8 meet or exceed your CCPA rights, including the right to know, delete, correct, and non-discrimination. Other jurisdictions: the GDPR-level rights in §8 are applied to you as written — no separate request process, no reduced version.

12. Changes

Material changes update the effective date above and are noted here. Because this policy is our global baseline, we won't weaken it regionally or quietly.


Terms of Service.

The rules for using this site and the Etch early-access program.

1. Agreement

By using projectetch.com or joining the early-access program, you agree to these terms. If you're acting for a company, you confirm you have authority to bind it. If you don't agree, don't use the site.

2. What this covers

These terms cover this website and pre-launch programs (VIP list, early access, pilots). When Etch launches commercially, paid use of the platform will be governed by a subscription agreement; the Salesforce products are governed by a direct license agreement (via Procloud Labs or its partners) or, once listed, the applicable AppExchange terms. Those agreements supersede these terms for product use.

3. Early access & beta

Early-access and pilot versions of Etch are provided as is, may change or break, and may be discontinued. Don't rely on pre-release versions as your only system of record — the permanence guarantees we market apply to the generally available product under a signed agreement, not to betas.

4. Acceptable use

  • Don't attempt to breach, probe, or overload the site or any Etch service.
  • Don't misrepresent who you are when contacting us or requesting access.
  • Don't scrape or reproduce the site's content for a competing commercial purpose.

5. Intellectual property

Etch, the Etch wordmark, the product names (Etch.Taxonomy, Etch.Brief, Etch.Vault, Etch.Intelligence, Etch.Taxonomy for Salesforce, Etch.Monitoring for Salesforce), and all site content are owned by Procloud Labs. Salesforce, Marketing Cloud, and AppExchange are trademarks of Salesforce, Inc. — we're independent of Salesforce. Nothing here grants you a license to our marks.

6. Feedback

If you send us ideas or feedback, you give us a perpetual, royalty-free license to use them without obligation — that's what lets us build suggestions into the product. We won't claim ownership of your underlying confidential business information.

7. Disclaimers

The site and pre-release services are provided "as is" and "as available," without warranties of any kind, express or implied, including merchantability, fitness for a particular purpose, and non-infringement. Content on this site describes a product in development; features, pricing, and timelines may change.

8. Limitation of liability

To the maximum extent permitted by law, Procloud Labs will not be liable for indirect, incidental, special, consequential, or punitive damages, or lost profits or data, arising from your use of the site or pre-release services. Our total liability for any claim relating to the site is limited to $100 USD.

9. Termination

We may suspend or end access to the site or early-access program at any time for conduct that violates these terms. You can leave the VIP list or the program at any time.

10. Governing law

These terms are governed by the laws of the State of Michigan, USA, without regard to conflict-of-law rules. Disputes will be resolved in the state or federal courts located in Wayne County, Michigan.

11. Changes & contact

We may update these terms; material changes will be reflected in the effective date above. Questions: info@procloudlabs.com · Procloud Labs, 4444 2nd Ave, Detroit, MI 48201.

Plain-English note: this page exists so you know where you stand before launch. When Etch is generally available, customers get a real subscription agreement with the retention, audit, and data-protection commitments the product is built around.

Security.

How we protect this site today, and what the product ships with. A product built on "the permanent record" has to earn trust on security first.

1. This website

All traffic is encrypted in transit (TLS 1.2+). Data at rest is encrypted by our hosting provider. Administrative access is limited to named individuals, protected by MFA, and logged. We collect the minimum described in the Privacy Policy — the best protection for data is not holding it.

2. The Etch platform

  • Identity — single sign-on (SAML — Okta, Azure AD) with SCIM provisioning on Enterprise and Agency plans; MFA available on every plan; passkey support.
  • Tenant isolation — every record is workspace-scoped; cross-workspace access requires the account-layer roles Enterprise plans configure explicitly.
  • Immutability by design — System UIDs cannot be altered by anyone, including us; the audit log is append-only and exportable for legal review.
  • Least-privilege access — role-based permissions (Owner, Admin, Editor, Viewer) set per app and per workspace; external reviewers use scoped, expiring links and never receive workspace credentials.
  • Encryption — TLS in transit; encryption at rest; secrets in a managed vault, never in code.

3. Compliance roadmap

A SOC 2 Type II audit is part of our path to general availability; the report will be available to customers and serious prospects under NDA once issued. Data processing agreements (with the SCCs described in the Privacy Policy) are available for pilot customers now. A current subprocessor list is available on request.

4. Reporting a vulnerability

If you find a security issue in this site or any Etch service, email security@procloudlabs.com. We commit to acknowledging reports within 2 business days, we won't pursue good-faith researchers, and we'll credit you if you'd like. Please avoid accessing other people's data and give us reasonable time to fix before disclosure.

5. Incidents

If an incident creates risk to you or your data, we notify affected parties without undue delay and the relevant authority within 72 hours, per Articles 33–34 GDPR — see the Privacy Policy.