ClientPath Workspace Privacy Policy

Effective date: August 31, 2026

Bright Path Ventures Group ("Bright Path," "we," "us," or "our") provides ClientPath Workspace ("ClientPath" or the "App") and the ClientPath support pages on brightpathventuresgroup.com (the "Site"). This Privacy Policy explains how information is handled when you use the App, visit the Site, or contact support.

## 1. Summary

- ClientPath stores App records locally on your device by default.

- Optional iCloud synchronization uses the private CloudKit database associated with your Apple Account.

- ClientPath does not operate an advertising network and does not use App records for targeted advertising or cross-app tracking.

- ClientPath's Apple Intelligence features use Apple's Foundation Models framework. The current App implementation uses Apple's system language model and does not send prompts or model responses to a Bright Path server.

- Bright Path receives information you voluntarily submit through the ClientPath support form. Squarespace also processes website and form information to host and operate the Site.

- We do not sell personal information or share it for cross-context behavioral advertising.

## 2. Information Entered Into ClientPath

ClientPath lets the device owner create and manage information for business and professional purposes. Depending on how the App is used, this may include:

- Client identity and contact information, such as names, email addresses, telephone numbers, dates of birth, state, postal code, occupation, and household notes.

- Financial and planning information, such as income, net worth, budgets, estimated needs, goals, risk tolerance, time horizon, experience, existing-product notes, and other user-entered notes.

- Practice-management information, such as pipeline stage, follow-ups, communication and activity notes, related persons, document-request metadata, workflows, policies, reference-number last four digits, commissions, professional credentials, approvals, service schedules, life events, close-outs, and outcomes.

- Product-catalog information, matching rules, product-source URLs, downloaded source materials, retrieval dates, document fingerprints, comparisons, disclosures, and notes.

- Organization settings, custom templates, and organization branding.

The person or organization using ClientPath decides what to enter and is responsible for having an appropriate legal basis, authorization, and business process for any information about clients or other individuals. Do not enter Social Security numbers, complete financial-account numbers, passwords, medical records, or other information that your business is not authorized and prepared to protect.

## 3. How App Information Is Stored and Processed

### Local storage

App records are stored locally on the user's device by default. Bright Path does not operate a separate server that receives or stores those App records.

### Optional private iCloud synchronization

If the user enables iCloud synchronization, supported App records synchronize through Apple's CloudKit service using the private database associated with the user's Apple Account. Apple processes that information under its own terms and privacy policy. Bright Path does not use the private CloudKit database for advertising or marketing.

### Apple Intelligence

On supported devices, ClientPath may use Apple's Foundation Models framework to create editable product-catalog drafts or review a pre-filtered set of product candidates. The current App implementation uses Apple's system language model and does not transmit prompts or generated responses to a Bright Path server. AI output may be incomplete or incorrect and must be reviewed by the user.

### Product discovery and external websites

When the user starts an official-source search, ClientPath may open a Google search in the user's browser. When the user directs ClientPath to download an official HTML, text, or PDF source, the App connects to the selected website. Google and the selected website may receive ordinary network information, such as the requested URL, IP address, device or browser information, and time of access. Their own privacy policies apply.

### Purchases

Apple processes ClientPath Pro purchases and purchase restoration. Bright Path does not receive the user's complete payment-card information. The App receives purchase and entitlement status needed to unlock Pro features. Apple may provide Bright Path with sales, proceeds, and transaction reporting through App Store Connect.

### User-directed imports, exports, and sharing

The user can import catalog files, export backups or catalogs, and share summaries using Apple's system sharing tools. These actions are initiated and controlled by the user. Information sent to a selected destination is governed by that destination's privacy practices.

## 4. Information Collected Through the Site and Support

If you submit the ClientPath support form, we collect the information you provide, which may include your name, email address, device type, operating-system version, App version, and support message. Please do not submit client information or other sensitive professional records through the support form.

The Site is hosted by Squarespace. Squarespace may process information needed to provide website hosting, security, form delivery, contact management, spam prevention, and site analytics. This may include IP address, browser and device information, pages viewed, timestamps, cookies, and form-submission information. When a required email field is used, Squarespace may store the submitter and submission details in the Site's Contacts panel and deliver a copy to the Site owner's configured email address.

We do not add support-form submitters to marketing lists unless they separately and affirmatively request marketing communications.

## 5. How We Use Information We Receive

We use information received through the Site, Apple reporting, or direct support communications to:

- Respond to support requests and communicate about reported issues.

- Diagnose problems, maintain security, prevent abuse, and improve ClientPath.

- Administer purchases and understand aggregate App Store performance.

- Meet legal, accounting, tax, regulatory, and App Store obligations.

- Protect our rights, users, and services.

We do not use client records stored inside the App for advertising, data brokerage, or independent financial, insurance, healthcare, or eligibility decisions.

## 6. Disclosure to Service Providers and Other Parties

Information may be processed or disclosed in the following circumstances:

- Apple: App distribution, purchases, entitlement verification, optional private iCloud synchronization, system sharing, and Apple Intelligence features.

- Squarespace: Website hosting, security, forms, contact management, and website analytics.

- User-selected destinations: Websites, email services, storage providers, or recipients selected by the user through a link, export, or share action.

- Professional advisers and authorities: When reasonably necessary for legal advice, compliance, fraud prevention, security, enforcement of agreements, protection of rights or safety, or response to lawful process.

- Business transactions: In connection with a merger, financing, acquisition, reorganization, or sale of assets, subject to appropriate confidentiality and legal protections.

We require service providers handling information on our behalf to protect it consistently with their responsibilities, our instructions, and applicable law. Third-party services also operate under their own privacy policies.

## 7. Retention and Deletion

- Local App records: Remain on the device until the user edits or deletes them, deletes all App data using ClientPath, removes the App, or the operating system removes the data. Device backups may persist according to the user's Apple backup settings.

- Synced App records: When private iCloud synchronization is enabled, deletions made through ClientPath may synchronize through CloudKit. Users can also manage applicable iCloud data through their Apple Account and device settings.

- User-created exports: Remain wherever the user saves or shares them until the user deletes them from those destinations.

- Downloaded product sources: Remain in the App's local support directory until the related data or App data is removed.

- Support records: We retain support communications only as long as reasonably necessary to resolve the request, maintain security and service history, and meet legal obligations. Our target is to remove ordinary resolved support submissions within 24 months unless a longer period is reasonably necessary.

- Purchase and website records: Apple and Squarespace retain records according to their own policies and the settings of the applicable account.

To delete App records, open Settings > Sync, Export, and Delete Data in ClientPath. If iCloud synchronization is enabled, allow the deletion to synchronize before disabling sync or removing the App. To request deletion of information submitted directly to Bright Path through the Site, use the contact form at https://brightpathventuresgroup.com/clientpath-support and write "Privacy Request" at the beginning of the message.

## 8. Your Choices

You may:

- Choose what information to enter into ClientPath.

- Use local-only storage or opt into private iCloud synchronization.

- Disable iCloud synchronization for future App use.

- Enable or disable ClientPath's device-authentication privacy lock.

- Decline to use Apple Intelligence features.

- Export App records and product catalogs.

- Delete local and synchronized App records through the App.

- Control cookies and other website features through your browser and available Site controls.

- Contact us to request access to, correction of, or deletion of information that Bright Path directly holds about you.

We may need to verify a request before acting on it. Certain information may be retained where required or permitted by law, including for security, fraud prevention, dispute resolution, tax, accounting, or compliance purposes.

## 9. California Privacy Rights

Depending on applicable law and subject to legal exceptions, California residents may have rights to know about personal information collected, request access to or correction or deletion of personal information, opt out of sale or sharing, limit certain uses of sensitive personal information, and receive equal service without unlawful discrimination for exercising privacy rights.

During the preceding 12 months, the categories of personal information Bright Path may have received directly were identifiers and contact information, internet or electronic activity associated with the Site, commercial information supplied by Apple about purchases, and support communications voluntarily submitted by users. Sources include the individual, Squarespace, and Apple. We use these categories for the purposes described in this Policy and may disclose them to the service providers described above. We have not sold personal information or shared it for cross-context behavioral advertising.

To submit a California privacy request, use https://brightpathventuresgroup.com/clientpath-support and begin the message with "California Privacy Request." Authorized agents may submit a request, but we may require proof of authorization and verification of the consumer's identity.

## 10. Security

We use reasonable administrative and technical measures appropriate to the information we handle. No storage, transmission, or system is guaranteed to be completely secure. Users are responsible for securing their devices, Apple Accounts, exports, backups, and any professional records entered into ClientPath.

Squarespace states that forms sent over SSL-enabled domains are encrypted in transit. Squarespace form blocks are not designed as a HIPAA-compliant solution. Do not submit protected health information or other sensitive client records through the support form.

## 11. Children's Privacy

ClientPath is intended for business and professional users and is not directed to children under 13. We do not knowingly solicit personal information from children through the Site. If you believe a child has submitted information to us, contact us so we can review and delete it where appropriate.

## 12. International Use

Bright Path and its service providers may process website and support information in the United States or other locations where they operate. Privacy laws may differ from those in the user's location. Organizations using ClientPath are responsible for determining whether their own use of client information complies with the laws and professional obligations that apply to them.

## 13. Changes to This Policy

We may update this Privacy Policy when ClientPath, the Site, our service providers, or legal requirements change. We will post the updated policy at this URL and revise the effective date. Material changes will be communicated when required by law.

## 14. Contact Us

For privacy questions or requests, visit:

https://brightpathventuresgroup.com/clientpath-support

Please begin the message with "Privacy Request" and do not include client records or other sensitive information.

## 15. Third-Party Privacy Information

- Apple Privacy Policy: https://www.apple.com/legal/privacy/

- Squarespace Privacy Policy: https://www.squarespace.com/privacy

© 2026 Bright Path Ventures Group. All rights reserved.