This Privacy Policy describes how Vizion Investments LLC ("Company", "we", "us", "our"), operator of E&P Directory at epdirectory.com, collects, uses, discloses, and protects information about users of our Platform.
This Policy applies to all users of the Platform, including Engineers, Procurement Professionals, Suppliers, and visitors to epdirectory.com. It covers information collected through the Platform, our emails, and any related services.
This Platform is designed for business-to-business (B2B) commercial use. Information you provide is primarily business or professional in nature. Where personal data is incidentally collected, we handle it in accordance with this Policy.
| Category | Examples | Who Provides It |
|---|---|---|
| Account Information | Name, email address, company name, phone number, role (engineer/supplier) | All users at registration |
| Professional Profile | Company specialties, certifications, capabilities, years in business | Suppliers |
| RFQ Content | Project descriptions, technical specifications, budget ranges, timelines | Engineers |
| Quote Data | Pricing, delivery terms, warranty terms, conditions | Suppliers |
| Communications | Messages sent through the Platform, support emails | All users |
| Payment Information | Billing address, last 4 digits of card (full card data held by Stripe) | Paying subscribers |
| Ratings and Reviews | Star ratings, written comments about suppliers | Engineers |
| Job Postings | Job titles, descriptions, salary ranges, application email | Suppliers |
| Jim Chat Conversations | Questions and messages submitted to the AI assistant | All users |
| Advertising Inquiries | Company name, contact person, advertising interest | Prospective advertisers |
| Purpose | Legal Basis (where applicable) |
|---|---|
| Provide, operate, and maintain the Platform and its features | Contract performance |
| Process payments and manage subscriptions | Contract performance |
| Match Engineers with relevant Suppliers via AI scoring | Contract performance / Legitimate interest |
| Power Jim AI assistant responses using platform context | Contract performance / Consent |
| Generate aggregated price intelligence and market analytics | Legitimate interest |
| Send transactional emails (account, billing, RFQ notifications) | Contract performance |
| Send marketing and promotional communications (with opt-out) | Legitimate interest / Consent |
| Detect and prevent fraud, abuse, and security incidents | Legitimate interest / Legal obligation |
| Comply with legal obligations and respond to lawful requests | Legal obligation |
| Improve our AI algorithms and platform features | Legitimate interest |
| Analyse Platform usage and performance | Legitimate interest |
We do not sell your personal information to third parties for their own marketing purposes.
The Platform is designed to facilitate connections between Engineers and Suppliers. The following information is visible to other users as part of the Platform's core function:
We share information with trusted service providers who process it on our behalf:
| Provider | Purpose | Data Shared |
|---|---|---|
| Stripe, Inc. | Payment processing | Billing information, subscription events |
| Anthropic, PBC | Jim AI assistant (LLM processing) | Chat messages, platform context (anonymised) |
| Render Services, Inc. | Cloud hosting and infrastructure | All Platform data (infrastructure level) |
| Resend | Transactional email delivery | Email address, email content |
| Telegram | Internal operational notifications | Advertising inquiry data, operational alerts |
We may disclose your information if required by law, regulation, legal process, or governmental request, or if we believe disclosure is necessary to protect the rights, property, or safety of the Company, our users, or others.
If we are involved in a merger, acquisition, asset sale, or similar transaction, your information may be transferred as part of that transaction. We will notify you before your information becomes subject to a materially different privacy policy.
We may share your information in other ways with your explicit consent.
When you use Jim, your messages and relevant platform context (your role, active RFQs, platform statistics) are transmitted to Anthropic, PBC for processing via their API. We do not transmit your full name, payment information, or contact details to Anthropic.
Anthropic processes this data in accordance with their API data usage policies. As of the date of this Policy, Anthropic does not use API inputs to train their models by default. You should review Anthropic's current privacy policy for the most up-to-date information.
Jim conversation history is stored on our servers to provide conversation continuity within a session. We may review conversation logs for safety monitoring, abuse prevention, and service improvement.
The 40-point supplier scoring algorithm processes RFQ requirements and supplier data to generate match scores. This processing occurs within our infrastructure and no data is sent to third parties for scoring purposes.
| Cookie Type | Purpose | Duration | Can be disabled? |
|---|---|---|---|
| Session / Authentication | Keep you logged in, maintain session state | Session / 30 days | No (required for Platform to function) |
| Preference | Remember your settings and preferences | 1 year | Yes (functionality may be affected) |
| Analytics | Understand how users interact with the Platform (aggregated) | Up to 2 years | Yes |
We do not use third-party advertising cookies or sell cookie data to advertisers. You can manage cookies through your browser settings. Note that disabling essential cookies will prevent you from using the Platform.
| Data Category | Retention Period | Reason |
|---|---|---|
| Account data | Duration of account + 3 years after closure | Legal compliance, dispute resolution |
| RFQ and quote data | 5 years from transaction date | Business records, dispute resolution |
| Payment records | 7 years | Tax and accounting legal requirements |
| Jim chat logs | 90 days rolling | Safety monitoring, service improvement |
| Ratings and reviews | Duration of supplier's active account + 2 years | Platform integrity |
| Server access logs | 90 days | Security monitoring |
| Marketing communications | Until opt-out + 30 days processing | CAN-SPAM / marketing compliance |
We may retain certain data longer where required by applicable law or where necessary for legitimate business purposes such as litigation holds.
We implement reasonable technical and organisational security measures to protect your information, including:
No method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security. In the event of a data breach affecting your rights, we will notify you as required by applicable state breach notification laws (see Section 16).
The Platform is not directed to, and we do not knowingly collect personal information from, individuals under the age of 18. If we become aware that we have collected personal information from a person under 18, we will delete that information promptly. If you believe we may have information from or about a minor, contact us at ads@epdirectory.com.
To exercise any of these rights, contact us at ads@epdirectory.com. We will respond within 30 days (or within the timeframe required by applicable state law). We will not discriminate against you for exercising your privacy rights.
Note: Some requests may be limited where retention is required by law, where the data is necessary to complete a transaction you requested, or where deletion would adversely affect another user's rights.
If you are a California resident, you have the following rights under the CCPA/CPRA:
Categories of personal information collected: Identifiers, commercial information, professional/employment information, internet/network activity, inferences drawn from the above.
Categories of sources: Directly from you, automatically from your use of the Platform, from payment processors.
Business or commercial purposes for collection: Providing the Platform, processing transactions, improving services, security, legal compliance.
Categories of third parties with whom we share: Service providers (Stripe, Anthropic, Render, Resend) under data processing agreements.
Do Not Sell or Share: We do not sell personal information. We do not share personal information for cross-context behavioural advertising.
To submit a CCPA request: email ads@epdirectory.com with subject line "CCPA Request". We will verify your identity before processing. You may designate an authorised agent to make a request on your behalf.
California residents may also contact the California Privacy Protection Agency (CPPA) at cppa.ca.gov.
Virginia residents have the right to: access, correct, delete, and obtain a copy of personal data; opt out of processing for targeted advertising, sale, or profiling for decisions with legal or similarly significant effects.
We do not process personal data for targeted advertising, sell personal data, or use personal data for profiling in furtherance of decisions with legal or similarly significant effects on consumers.
To exercise your rights, email ads@epdirectory.com. We will respond within 45 days, extendable by an additional 45 days with notice. If we decline to take action on a request, you may appeal by replying to our response. If the appeal is denied, you may contact the Virginia Attorney General at oag.state.va.us.
Colorado residents have the right to: access, correct, delete, and obtain a portable copy of personal data; opt out of processing for targeted advertising, sale of personal data, and profiling.
Universal Opt-Out: We honour the Global Privacy Control (GPC) signal as an opt-out from the sale of personal data and targeted advertising where technically feasible.
We do not sell personal data or use it for targeted advertising or profiling with significant effects. To exercise other rights, email ads@epdirectory.com. Response time: 45 days (extendable by 45 days). Appeals may be submitted to the Colorado Attorney General at coag.gov.
Connecticut residents have the right to: access, correct, delete, and obtain a portable copy of personal data; opt out of targeted advertising, sale of personal data, and profiling for decisions with significant effects.
We do not sell personal data or process it for targeted advertising or consequential profiling. To exercise your rights, email ads@epdirectory.com. Appeals may be submitted to the Connecticut Attorney General.
Texas residents have the right to: access, correct, delete, and obtain a portable copy of personal data; opt out of processing for targeted advertising, sale of personal data, or profiling for consequential decisions.
We do not sell personal data, process it for targeted advertising, or use it for consequential profiling. To exercise your rights, email ads@epdirectory.com. We will respond within 45 days. Appeals may be submitted to the Texas Attorney General.
The following states have enacted or are in the process of enacting comprehensive privacy laws. We are committed to compliance with all applicable state privacy legislation:
| State | Law | Key Right / Note |
|---|---|---|
| Montana | Montana Consumer Data Privacy Act (MCDPA, eff. Oct 2024) | Access, correct, delete, portability, opt-out of sale/targeted advertising |
| Oregon | Oregon Consumer Privacy Act (OCPA, eff. Jul 2024) | Broad rights; covers non-profit data in some cases |
| Indiana | Indiana Consumer Data Protection Act (ICDPA, eff. Jan 2026) | Access, correct, delete, portability, opt-out |
| Iowa | Iowa Consumer Data Protection Act (ICDPA, eff. Jan 2025) | Access, delete, portability, opt-out of sale/targeted advertising |
| Tennessee | Tennessee Information Protection Act (TIPA, eff. Jul 2025) | Access, correct, delete, portability, opt-out |
| Minnesota | Minnesota Consumer Data Privacy Act (MCDPA, eff. Jul 2025) | Access, correct, delete, portability, opt-out; includes right to question profiling |
| Maryland | Maryland Online Data Privacy Act (MODPA, eff. Oct 2025) | Among the strictest: limits data minimisation requirements |
| Nebraska | Nebraska Data Privacy Act (NDPA, eff. Jan 2025) | Access, correct, delete, portability, opt-out |
| New Hampshire | New Hampshire Privacy Act (NHPA, eff. Jan 2025) | Access, correct, delete, portability, opt-out |
| New Jersey | New Jersey Data Privacy Act (NJDPA, eff. Jan 2025) | Access, correct, delete, portability, opt-out; honours universal opt-out |
| Delaware | Delaware Personal Data Privacy Act (DPDPA, eff. Jan 2025) | Access, correct, delete, portability, opt-out; applies to ages 13–17 data too |
| Kentucky | Kentucky Consumer Data Protection Act (KCDPA, eff. Jan 2026) | Access, correct, delete, portability, opt-out |
| All 50 States | State Breach Notification Laws | We will notify affected residents of qualifying data breaches within the timeframe required by each state's law (typically 30–90 days). Most states require notification where the breach compromises unencrypted personal information. |
Regardless of your state of residence, you may contact us at ads@epdirectory.com to exercise privacy rights. We will apply rights consistent with applicable law for your state.
The Platform is operated from the United States. If you access the Platform from outside the United States, please be aware that your information may be transferred to and processed in the United States, where data protection laws may differ from those in your country.
We do not specifically target users outside the United States. The Platform is designed for US-based B2B commercial use. If you are located in the European Economic Area (EEA), United Kingdom, or other jurisdictions with transfer restrictions, please be aware that by using the Platform you acknowledge this data transfer.
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated Policy on the Platform with a revised "Last Updated" date and, for registered users, by sending an email notification at least 14 days before the changes take effect.
State privacy laws change frequently. We review this Policy at least annually and update it to reflect new legal requirements. We recommend reviewing this Policy periodically.
For privacy questions, requests, or complaints: