Privacy Policy

Effective Date: June 1st, 2025

At Gradly, your privacy is our priority. This Privacy Policy outlines how we collect, use, and protect your personal information when you use our services. By accessing or using Gradly, you agree to the collection and use of your information as described in this policy.

1. Introduction and Scope

This Privacy Policy describes how Gradly ("we," "us," "our") collects, uses, processes, and protects user personal information through our document-enhancement platform, scholarship-matching service, and related applications (the "Service"). Gradly prioritizes user privacy, adheres to applicable privacy regulations, and designs privacy protections into all our processes.

2. Information Collected

Gradly collects only information voluntarily provided by users or institutions necessary to deliver our services:

Contact information: email address, name, institution affiliation.

Document data: resumes, essays, personal statements, and user-generated content.

Scholarship matching data: academic background, demographics, interests, and achievements voluntarily shared by users.

Technical data: IP addresses, device/browser information collected for security and operational purposes.

We do NOT collect genetic, biometric, behaviometric (e.g., facial recognition or fingerprints), or other sensitive personal data.

3. How We Use Your Information

Gradly processes personal data solely for these explicit purposes:

Enhancing and generating documents (resumes, essays, applications).

Matching users with relevant scholarship opportunities.

Facilitating optional, explicit sharing of user data with authorized institutional administrators.

Internal analytics provided in aggregate to institutional partners.

Gradly does not use or disclose data for automated decision-making without human review.

4. Legal and Regulatory Compliance

Gradly complies with the Family Educational Rights and Privacy Act (FERPA).

We adhere to applicable state privacy laws (such as CCPA), complying with user rights and providing appropriate notices and disclosures.

Gradly will comply fully with applicable breach notification laws and promptly notify affected individuals and institutions in case of a data breach.

5. Data Sharing and Third Parties

Gradly never sells, rents, or shares personal information with third parties except as follows:

With explicit user consent for institutional administrator review.

With secure subprocessors under strict confidentiality agreements for the purpose of service delivery only.

In response to a valid, legally enforceable warrant or court order.

No third-party analytics or advertising networks receive user data.

6. Data Ownership and Control

Users retain ownership and complete control over their personal information and documents.

Users may review, update, delete, or withdraw consent to their data at any time. Gradly promptly complies with deletion or stop-processing requests.

Gradly maintains accurate, complete, and relevant personal information strictly for the stated purposes.

7. AI and Data Processing

Gradly utilizes commercial enterprise-grade AI services.

Certain user inputs are retained for purposes of delivering high quality services for our users.

Users may not opt-out of AI-driven functionality.

8. Privacy-by-Design and Risk Management

Privacy considerations are embedded into Gradly’s software development lifecycle (SDLC), with routine code reviews to identify privacy and ethical risks.

Third-party subprocessors are evaluated to ensure compliance with data privacy regulations. Agreements require subprocessors to maintain appropriate privacy and security standards.

9. Data Security

Gradly encrypts all user data (TLS 1.2+ in transit, AES-256 at rest).

We limit data access strictly to authorized internal team members necessary for service delivery.

Gradly follows established protocols for patching, risk mitigation, and incident response.

10. Privacy Training and Awareness

Gradly team members maintain active, ongoing privacy and security awareness practices.

All future team members will receive mandatory privacy and data ethics training during onboarding.

11. Privacy Impact and Assessments

Gradly regularly evaluates privacy impacts associated with our data processing practices, including assessments of third-party subprocessors.

We proactively manage privacy risks and document our privacy management processes.

12. Breach Notification and Incident Management

Gradly maintains a documented incident response plan, ensuring swift action in the event of unauthorized access or data breaches, including timely notifications to affected users, institutions, and regulatory authorities as applicable.

13. Data Retention and Disposal

User personal data is retained only for the duration necessary to fulfill its stated purpose, comply with agreements, or as required by law.

Data is securely disposed of after the retention period concludes.

14. Policy Violations and Complaints

Gradly takes all complaints and privacy-related concerns seriously. Any inquiries or complaints can be sent directly to the designated contact below.

We commit to addressing privacy complaints promptly and transparently.

15. Changes to this Policy

We reserve the right to update this Privacy Policy periodically. Material changes will be communicated through email notifications and clearly indicated on our platform.

16. Contact Us

If you have any questions or concerns about this Privacy Policy, please contact us at:

Email: info@gogradly.com

Mailing Address: 1016 Lois Ln., Bowling Green, KY 42104

Thank you for trusting Gradly to support your educational journey!