The short version. This policy covers information collected through this website. We use a small set of measurement technologies here: analytics to understand how the site is used, advertising measurement tags to see whether our campaigns work, and a service that matches the IP address in our server logs to the organization it belongs to. The last one identifies organizations, not individuals.

We do not sell personal information. We do not use website data to build advertising profiles of individuals. Visitors in the European Economic Area and the United Kingdom are asked for consent before any non-essential technology is set, and consent can be withdrawn at any time.

1. Who we are

HeyDonto AI Technology is the trade name of VMC MAR COM Inc., a Delaware corporation with offices in Knoxville, Tennessee and in Berlin, Germany ("HeyDonto," "we," "us," "our"). We are a holding company that builds and operates focused AI companies for healthcare and science. We are the controller for the personal data described in this policy.

For any question about this policy, or to exercise a right under it, email [email protected].

2. What this policy covers

This policy covers heydonto.com and the pages served from it. It does not cover the websites, consoles, or products operated by our portfolio companies. Each of those publishes its own privacy policy, and that policy governs when you are on that site or using that product.

This policy also does not cover data handled under a signed commercial agreement. Where a customer agreement, a business associate agreement, or a data processing agreement addresses a subject covered here, that agreement governs for that customer's data.

3. What we collect

Information you send us.
If you email us, submit an inquiry, or book a meeting, we receive what you choose to include. That is typically your name, work email address, organization, role, and the substance of your message, plus the details needed to schedule and hold the meeting.
Server logs.
Our hosting provider records requests to the site. Log records may include IP address, browser and device type, operating system, the page requested, the referring page, and a timestamp. We use these for security, abuse prevention, capacity planning, and diagnosing errors.
Measurement data.
Where the technologies in section 4 are active, we collect information about how the site is used: pages viewed, time on page, scroll depth, links and buttons clicked, the source that referred you, an approximate location derived from IP address at roughly the city level, and general device and browser characteristics. This is collected through cookies, pixels, and similar technologies, and is analysed in aggregate.
Organization-level identification.
We use a third-party service that matches the IP address in our server logs to the organization that address belongs to. It returns organization-level attributes such as company name, industry, approximate size, and general location. It identifies organizations, not individuals. It does not tell us who you are, and it does not return a name, an email address, a phone number, or any other individual identifier. We use it to understand which kinds of businesses are interested in what we build.

4. Cookies and similar technologies

We use four categories of technology on this site. We describe each one plainly so you can decide about it.

Essential.
Cookies and storage strictly necessary to serve and secure the site, route your request, remember your privacy choices, and protect against abuse. These are always active. They cannot be switched off without breaking the site.
Analytics and measurement.
We use a third-party analytics provider to understand how this site is used: which pages get read, how visitors arrive, which paths they take, and where they leave. This uses cookies and similar identifiers that persist between visits so that repeat visits can be recognised as repeat visits. We use the results to decide what to write and what to fix. Analytics is not essential, and you can decline it.
Advertising measurement.
We run campaigns on a professional social platform, and we place that platform's measurement tag on this site. It does two things. First, it measures campaign performance, so we can tell whether people who saw an advertisement later visited the site and what they did when they got here. Second, it lets us build audiences at the platform, so we can show later advertisements to people who have visited this site or to audiences the platform considers similar. Audience membership is held and applied by the advertising platform under its own privacy policy. Advertising measurement is not essential, and you can decline it.
Organization identification.
The service described in section 3 that resolves a logged IP address to an organization. It operates on server-side log data rather than on a cookie set in your browser, but we treat it as a non-essential technology and gate it in the same way. It is organization-level only.

Consent and control

If you are in the European Economic Area, the United Kingdom, or Switzerland, we ask for your consent before any non-essential technology is set, and nothing in the analytics, advertising measurement, or organization identification categories runs until you give it. You can withdraw consent at any time, and withdrawing is as easy as giving it. Use the cookie settings control on this site.

Elsewhere, non-essential technologies may be active by default, and you can turn them off at any time using the same control. We honour the Global Privacy Control signal where your browser sends one, and we treat it as a valid request to opt out of sharing for cross-context behavioral advertising.

You also have controls outside this site. Most browsers let you block or delete cookies. Our analytics provider publishes a browser opt-out. The advertising platform provides ad and data settings in your account there. Blocking cookies broadly may affect how this and other sites behave.

5. What we do not do

  • We do not sell personal information. We do not exchange it for money.
  • We do not use website data to build advertising profiles of individuals. Our measurement is aggregate, and our audience work happens at the audience level inside the advertising platform.
  • We do not deploy any tool that identifies an individual visitor by name, email address, or personal identity from an anonymous visit. If that ever changes, we will change this policy first and say so.
  • We do not use information collected through this website to train AI models.
  • We do not knowingly collect personal information from children under 16 through this site.
  • We do not seek precise geolocation, biometric, genetic, or health information through this site, and you should not send it to us here.

This website is not a channel for protected health information

Do not send patient records, clinical data, claims data, or other protected health information through this site or by email to us. If a dataset needs to move as part of an evaluation, the responsible portfolio company will put the appropriate agreements and a secure channel in place first.

6. Why we use it, and on what basis

  • To answer your inquiry and, where relevant, continue a commercial conversation.
  • To operate, secure, maintain, and debug the website.
  • To understand how the site is used and to improve what we publish.
  • To plan, run, and measure marketing campaigns, and to understand which kinds of organizations are interested in our work.
  • To meet legal, regulatory, tax, accounting, and contractual obligations, and to establish, exercise, or defend legal claims.

Where the EU or UK GDPR applies, our lawful bases are: your consent, for analytics, advertising measurement, and organization identification; our legitimate interests in operating and securing the site and in responding to business inquiries, where those interests are not overridden by your rights; the performance of steps taken at your request before entering a contract; and compliance with legal obligations.

7. Who we share it with

We use a small number of third-party providers to run this site and our business. We name them here by function rather than by brand, because providers change:

  • A hosting and content delivery provider.
  • An email and productivity provider.
  • A customer relationship management and scheduling provider.
  • An analytics provider.
  • An advertising platform, for campaign delivery and measurement.
  • An organization-identification provider.

A current list of the providers that handle personal data for this website is available on request from [email protected]. Providers process information only as needed to deliver their service to us and under contractual confidentiality and security obligations. Where a provider processes personal data subject to the GDPR, we put an appropriate data processing agreement and transfer mechanism in place.

We may also disclose information where the law requires it, to respond to lawful requests from public authorities, to enforce our terms, to protect the rights and safety of people or our business, and to a counterparty and its advisers in connection with a financing, acquisition, or other corporate transaction, subject to confidentiality.

8. Notice at collection for California residents

This section is our notice at collection under the California Consumer Privacy Act as amended by the California Privacy Rights Act. It applies to California residents, and it applies to you whether you are here as an individual or in a professional capacity. California's exemption for business-to-business contacts expired on 1 January 2023. A business contact browsing this site is a consumer with the full set of rights below.

Category collected Examples Purpose Recipients Retention
Identifiers Name, work email address, organization, role, IP address, cookie and device identifiers Responding to inquiries, site security, analytics, advertising measurement Hosting, email, CRM and scheduling, analytics, advertising platform Correspondence for the life of the relationship plus the period needed for legal and accounting obligations; identifiers held in logs and measurement tools on the shorter schedules in section 10
Commercial information The substance of your inquiry, products discussed, meetings requested Responding to inquiries and continuing a commercial conversation Email, CRM and scheduling Life of the relationship plus legal and accounting obligations
Internet or other electronic network activity Pages viewed, time on page, clicks, referring source, browser and device characteristics Operating and securing the site, analytics, advertising measurement Hosting, analytics, advertising platform Short rolling retention for server logs; provider-set retention for measurement data
Geolocation data (approximate) City-level location derived from IP address. We do not collect precise geolocation. Analytics, campaign measurement, fraud and abuse prevention Hosting, analytics, advertising platform, organization-identification provider As for the log or measurement record it belongs to
Professional or employment-related information Employer, job title, industry, organization size, where you provide it or where it is derived at the organization level Qualifying and routing inquiries, understanding which organizations are interested CRM, organization-identification provider Reviewed periodically and deleted when no longer useful as a business record

We do not collect sensitive personal information as that term is defined in the CCPA through this website, and we do not use or disclose personal information for purposes other than those listed above without giving notice first.

Selling and sharing

We do not sell personal information. We do disclose identifiers and online activity data to an advertising platform for campaign measurement and for building audiences, and under California law that activity can count as sharing for cross-context behavioral advertising. We treat it that way rather than argue about it. You can opt out of that sharing at any time using the cookie settings control on this site, and we honour the Global Privacy Control signal as an opt-out request. Opting out does not stop us from responding to an inquiry you send us.

Your rights

  • Know. Request the categories and specific pieces of personal information we have collected, the sources, the purposes, and the categories of third parties we disclosed it to.
  • Delete. Request deletion of personal information we collected from you, subject to the exceptions the statute allows.
  • Correct. Request correction of inaccurate personal information.
  • Opt out of sale or sharing. Direct us to stop sharing your personal information for cross-context behavioral advertising.
  • Limit use of sensitive personal information. We do not collect it here, so there is nothing to limit, but the right stands.
  • Non-discrimination. We will not deny you service, charge you a different price, or give you a lesser experience for exercising any of these rights.

To exercise a right, email [email protected] with the request and enough detail for us to locate the information. We may need to verify your identity before we act, and we will not use verification information for anything else. We respond within 45 days and will tell you if we need the additional 45 days the statute allows. An authorized agent may submit a request on your behalf with written proof of authority.

Residents of other states with comprehensive privacy laws, including Colorado, Connecticut, Virginia, Utah, Texas, and Oregon, have a comparable set of rights and can use the same address to exercise them.

9. EEA, UK, and Swiss visitors

We have operations in Germany, so the GDPR applies to this website directly rather than as an edge case. We treat EEA, UK, and Swiss visitors accordingly.

You may request access to the personal data we hold about you, correction of inaccurate data, deletion, restriction of processing, and portability. You may object to processing carried out on the basis of our legitimate interests. Where we rely on consent, you may withdraw it at any time, and withdrawal does not affect the lawfulness of what we did before. To make a request, email [email protected].

You also have the right to lodge a complaint with a supervisory authority in the country where you live or work, or where you believe an infringement occurred. We would rather hear from you first, but that right is yours and we will not discourage it.

10. How long we keep it

  • Inquiry correspondence and CRM records. Kept for as long as needed to handle the relationship, then for as long as reasonably necessary to meet legal, tax, accounting, and dispute-resolution obligations, then deleted or de-identified.
  • Server logs. Retained on a short rolling basis for security and diagnostics.
  • Analytics data. We configure user-level and event-level retention to the shortest period our analytics provider offers. Aggregate reporting that no longer identifies anyone may be kept longer.
  • Advertising measurement data and audiences. Retained according to the advertising platform's settings, which cap how long a visitor can remain in an audience.
  • Organization-level records. Kept as business-interest records, reviewed periodically, and removed when no longer useful.

11. International transfers

We are headquartered in the United States and have operations in Germany. Personal data may be processed in either place and by providers in other countries. Where personal data is transferred out of the EEA, the UK, or Switzerland, we rely on an appropriate transfer mechanism, which is normally the European Commission's Standard Contractual Clauses together with the UK International Data Transfer Addendum, backed by encryption in transit and access controls. You can ask us for information about the mechanism used for a particular transfer.

12. Security

We maintain administrative, technical, and physical safeguards appropriate to the information we handle, including access control with periodic review, encryption in transit, personnel screening and training, secure development practices, incident response, and third-party risk management. Where an external examination of a control environment is in progress, we describe its status plainly and do not claim a certification we do not hold. No system is perfectly secure, and we do not pretend otherwise.

13. Children

This website is for business audiences. It is not directed to children, and we do not knowingly collect personal information from anyone under 16. If you believe a child has sent us personal information, email [email protected] and we will delete it.

14. Other sites we link to

We link to the sites of our portfolio companies and to third-party sites including publishers, standards bodies, and scheduling tools. We do not control them. Their own privacy policies apply when you get there, and you should read the one that matters to you.

15. Changes

We may update this policy. The date at the top reflects the current version. If we make a material change, in particular if we add a technology that collects something new, we will update this policy before the change takes effect and take reasonable steps to bring it to your attention.

16. Contact

VMC MAR COM Inc. DBA HeyDonto AI Technology
Knoxville, Tennessee, United States · Berlin, Germany
[email protected]
Press: [email protected]

Related

Terms of Use governs your use of this website. Our portfolio companies publish their own privacy policies, which govern their own sites and products.