ConfidentCompliance.ai - This Privacy Policy explains how we collect, use, and protect your information when you use our iATTEST CMMC compliance management platform.
DIT4E, LLC DBA ConfidentCompliance.ai (“Company”) provides an AI-powered CMMC compliance management platform, iATTEST (“Service”).
This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service. By using the Service, you consent to the collection and use of information in accordance with this Privacy Policy. If you do not agree with the terms of this Privacy Policy, please do not access or use the Service.
This Privacy Policy complies with the General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), and other applicable privacy laws.
Contact: privacy@confidentcompliance.ai
Account Information
Company Profile Information
Compliance Program Information
Support Communications
THE SERVICE IS NOT DESIGNED TO COLLECT, STORE, OR PROCESS:
You are prohibited from uploading such information to the Service. See our Terms of Service Section 6 for complete data restrictions. The Service helps you document your compliance program — it does not serve as a repository for the sensitive data you are protecting.
The Company does not store full payment card numbers, CVVs, or complete card details on our systems. Payment is processed by a secure third party (sub processor). The Company has the right to change or modify agreements with third party vendors at any time without notice. If any vendor changes require updates to the Privacy Policy, Company will inform users of the privacy changes.
Usage Information
Technical Information
Cookies and Similar Technologies
Your compliance program descriptions and documentation content are processed by AI systems to:
Important: AI-generated outputs require your review and validation before use. You are responsible for the accuracy of any documentation submitted to the government or assessors. This is why the iATTEST CMMC application was built as a human-in-the-loop solution. It increases efficiency but does not replace the need for your review prior to attestation.
We may use anonymized and/or aggregated data that cannot identify you or your organization for research, benchmarking, and service improvement purposes.
This Service does not process, store, or transmit Controlled Unclassified Information (CUI).
Our infrastructure is not certified to NIST SP 800-171, CMMC Level 2, or FedRAMP standards required for CUI handling.
You must maintain CUI in your own appropriately secured environment. The Service helps you document and manage your compliance program — it does not serve as a repository for the sensitive government data you are protecting.
While the Service assists with CMMC Level 1 compliance (which addresses FCI protection), do not upload actual FCI documents. Instead, describe your systems and controls rather than uploading source documents.
If you inadvertently upload CUI, classified information, or other prohibited data:
We may receive requests from government agencies related to your use of the Service. Our policy is to:
Your government contracts may impose flow-down requirements on service providers. If you require specific contractual provisions, please contact us at legal@confidentcompliance.ai to discuss your requirements before subscribing.
We retain your information for as long as necessary to provide the Service and fulfill the purposes described in this Privacy Policy:
| Data Type | Retention Period |
|---|---|
| Account and Compliance Data | While your account is active |
| Post-Cancellation | 90 days, then permanently deleted |
| Payment and Transaction Records | 7 years (tax/accounting requirements) |
| Support Communications | 3 years from resolution |
| Anonymized Analytics | Retained indefinitely |
| Backup Data | Purged within 30 days of primary deletion |
Exceptions:
Your Rights:
We implement security measures appropriate for business data and compliance program information:
Technical Measures
Administrative Measures
Breach Notification
IMPORTANT LIMITATION
These measures are designed for general business data and compliance program information. Our infrastructure is NOT certified for:
Do not rely on our security measures for protecting government-controlled information — that must remain in your own compliant environment.
No security measures are 100% effective. While we strive to protect your information, we cannot guarantee absolute security against all threats.
Depending on your location, you may have the following rights regarding your personal information:
To exercise any of these rights, contact us at privacy@confidentcompliance.ai. We will respond within 30 days (or sooner if required by applicable law).
If you are located in the European Union or European Economic Area, you have additional rights under the GDPR:
Legal Basis for Processing
Data Protection Officer — Contact our DPO at privacy@confidentcompliance.ai
Supervisory Authority — You have the right to lodge a complaint with your local data protection authority
Automated Decision-Making — We do not engage in solely automated decision-making that produces legal or similarly significant effects on you
If you are a California resident, you have specific rights under the CCPA:
To submit a CCPA request, contact privacy@confidentcompliance.ai or use the privacy controls in your Account Settings.
Your data is stored and processed in the United States on infrastructure located within US regions.
If you access the Service from outside the United States, your information will be transferred to and processed in the US. By using the Service, you consent to this transfer.
For EU/EEA Users:
For Defense Contractors:
Keeping compliance data on US-based infrastructure may be preferable or required for certain contract requirements. Our infrastructure is located in the continental United States.
The Service is designed for business use by defense contractors and related organizations. It is not intended for individuals under 18 years of age.
We do not knowingly collect personal information from anyone under 18. If you are a parent or guardian and believe a minor has provided us with personal information, please contact us at privacy@confidentcompliance.ai. We will take steps to remove such information promptly.
The Service may contain links to third-party websites, services, or resources not operated by us. These may include:
We are not responsible for the privacy practices of third-party sites. We encourage you to review their privacy policies before providing any personal information. Inclusion of a link does not imply endorsement.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.
What Constitutes a Material Change:
A “Material Change” is any modification that significantly affects your rights or how we handle your Personal Data, including but not limited to: changes in the categories of Personal Data collected, new purposes for data processing, alterations to data sharing practices with third parties, changes to your data subject rights, or modifications to our security practices that could impact data protection.
How We Notify You:
Your Continued Use:
Your continued use of the Service after the effective date of any changes constitutes your acceptance of the updated Privacy Policy. If you do not agree with changes, you should discontinue use and may request account deletion.
We encourage you to review this Privacy Policy periodically.
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices:
Privacy and Data Protection
privacy@confidentcompliance.ai
General Support
support@confidentcompliance.ai
Security Issues and Spillage Reports
security@confidentcompliance.ai
Legal Inquiries
legal@confidentcompliance.ai
We will respond to privacy requests within 30 days, or sooner if required by applicable law. Complex requests may require additional time, in which case we will notify you of the expected timeline.
California Civil Code Section 1798.83 permits California residents to request information about disclosure of personal information to third parties for direct marketing purposes. We do not disclose personal information to third parties for their direct marketing purposes.
Nevada residents may submit requests to opt out of the sale of personal information. We do not sell personal information. To submit a request, contact privacy@confidentcompliance.ai.
Residents of states with comprehensive privacy laws have rights similar to those described in Section 8. Contact privacy@confidentcompliance.ai to exercise your rights.
Last Updated: December 26, 2025
© 2025 DIT4E, LLC. All rights reserved.
If you have any questions about this document, please contact us at legal@confidentcompliance.ai