Pēq Client Privacy Statement

Last updated: August 12, 2026

This Client Privacy Statement describes how Incrementology, Inc. d/b/a Pēq (“Pēq”) processes data on behalf of its clients in connection with the Pēq measurement and analytics platform (the “Platform”), available at app.go-peq.com, and related services provided under a signed services agreement (a “Services Agreement”). This Statement supplements, and does not replace, the applicable Services Agreement and any information security or data processing addendum incorporated into it, which govern in the event of any conflict with this Statement. This Statement does not apply to Pēq’s public marketing website at peq.ai, which is addressed by Pēq’s separate Privacy Policy, available at https://peq.ai/privacy-policy.

1. Roles

With respect to data a client submits to or makes accessible to Pēq for purposes of the Platform (“Client Data”), the client acts as the business/controller and Pēq acts as a service provider (as defined under the CCPA and comparable state privacy laws) or processor (as defined under the GDPR, where applicable). Pēq processes Client Data solely to provide the Platform and related services, on the client’s documented instructions, and does not use Client Data for any independent purpose except as described in Section 3 below.

2. What Data Pēq Processes

Performance data. Clients provide marketing and sales performance data to Pēq in aggregated form—at minimum, store-by-SKU/UPC-by-campaign level, or an equivalent level of aggregation agreed with the client. Pēq does not request end-consumer personal information for this purpose. If an incoming data feed contains a customer-identifying field (for example, a loyalty or household ID, a hashed email address, or a device or advertising identifier), Pēq rejects that field before it is ingested into Pēq’s cloud environment.

Account Data. The only personal information Pēq processes in connection with the Platform is account and contact information belonging to a client’s authorized users of the Platform, or personnel who correspond with Pēq regarding onboarding, data integration, or support — namely, name, business email address, and related account or session metadata (“Account Data”).

Pēq does not require or request payment card data or protected health information from clients in connection with the Platform.

3. How Pēq Uses Client Data

Pēq uses Client Data solely to provide the Platform and related services to the applicable client, consistent with that client’s Services Agreement. Pēq does not sell Client Data. Pēq does not use Client Data, including in aggregated or de-identified form, for cross-client benchmarking, model training, product development, or any purpose outside a specific client’s Services Agreement, without that client’s separate prior written consent.

4. Infrastructure and Subprocessors

Pēq runs on Google Cloud Platform (GCP) within a dedicated Google Cloud Organization. Each client’s data is provisioned in a dedicated GCP project, with project-level access controls preventing cross-client access. Clients may send data to Pēq via SFTP (hosted by SFTP To Go), API integration, direct database connection, or automated email ingestion; each channel routes data to the client’s dedicated project. Further detail is available in Pēq’s Data Security Practices document, provided to clients upon request.

5. Data Location and Personnel Access

Client Data is stored in United States data center regions. Certain Pēq personnel who provide support, data integration, or engineering services may access Client Data remotely, including personnel located outside the United States. Such remote access requires a company-managed VPN connection with multi-factor authentication and an encrypted connection, and Client Data may not be downloaded to or stored on personal or unmanaged devices.

6. Retention and Deletion

Pēq retains Client Data for the duration of the applicable Services Agreement. Upon termination of a Services Agreement, or upon a client’s request during the term, Pēq will delete Client Data, including from active systems and backups, within thirty (30) days, unless a shorter timeline is agreed in a specific Services Agreement.

7. Security

Pēq’s security practices—including encryption in transit and at rest, project-level isolation between clients, centralized logging and monitoring, and least-privilege access controls—are described in Pēq’s Data Security Practices document, available to clients upon request. Pēq is pursuing SOC 2 Type II certification. In the interim, Pēq’s underlying infrastructure provider, Google Cloud Platform, maintains SOC 1 Type II, SOC 2 Type II, and SOC 3 reports, and ISO/IEC 27001, 27017, and 27018 certifications.

8. Individual Rights Requests

Because Pēq acts as a service provider or processor with respect to Client Data, Pēq does not respond directly to a request from an individual concerning Client Data unless authorized to do so by the applicable client or required by law. Pēq will notify the client of any such request it receives and will provide reasonable cooperation and assistance to enable the client to respond.

9. Changes to This Statement

Pēq may update this Statement from time to time to reflect changes in its practices. Where a specific client has a client-specific addendum addressing data processing (for example, an order form addendum modifying an information security and privacy addendum), that addendum controls over this general Statement to the extent of any conflict, solely with respect to that client’s services.

10. Contact

Questions about this Statement, or about how Pēq processes Client Data, may be directed to info@peq.ai, or to your Pēq account representative.