This Privacy Policy explains how Sisu Logistic, LLC (DBA Sisu IO) ("ClimbSuite," "we," "us") collects, uses, and shares personal information when you use the ClimbSuite platform and websites (the "Service"). For personal data we process on behalf of our customers (our customers' contacts/leads), the customer is the controller and we act as processor under the Data Processing Addendum.
1. Categories of information we collect, and why
- Account data (name, email, organization, billing details) — to create and secure your account and to bill you.
- Content & contacts you upload to run your business (e.g., your CRM contacts, course content, webinar recordings, video messages) — to provide the core Service to you.
- Usage data (log data, device/browser info, analytics about how the Service is used) — to secure, debug, and improve the Service.
- Cookies & similar tech — for sign-in, security (bot/abuse protection), and product analytics; see our Cookie Policy.
2. How we use information
To provide, secure, and improve the Service; to process payments; to communicate with you (service and, with consent where required, marketing messages); to provide support; to detect abuse and comply with law; and, where an organization enables it, to power AI-assisted features as described in §3 below.
3. AI features — how we use Anthropic
Some ClimbSuite features (for example, AI-assisted lesson/course-content generation) are powered by large language models. By default this uses Anthropic's Claude API; an organization admin can alternatively connect their own OpenAI or Google Gemini API key in Settings, in which case that vendor processes the request instead. When a Claude-powered feature is used, the relevant text you or your organization submits (e.g., a lesson outline prompt) is sent to Anthropic's API to generate a response; Anthropic acts as our subprocessor for that processing and does not use API inputs/outputs to train its models. AI features are opt-in per organization — they only run when an org admin has connected an AI provider in Settings → Integrations.
4. Google & YouTube API Services
When you connect a Google or YouTube account, you authorize us to access data from that account through Google APIs, requesting only the scopes needed for the features you connect: view your YouTube account (display your channel and videos so you can confirm the connected account and reference your content) and manage your YouTube videos (publish and schedule videos to your own channel at your direction). We access this data only after your explicit consent and use it solely to provide those features; we do not use it for advertising, do not sell it, and do not share or transfer it except as necessary to provide the service, to comply with law, or in a merger/acquisition with equivalent protections. Access tokens are stored securely.
Limited Use: our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. You can disconnect in-app at any time and revoke access at Google Account permissions; to request deletion of stored data use your account privacy/data-rights options. Your use of YouTube features is also governed by the YouTube Terms of Service and the Google Privacy Policy.
5. How we share information
- Service providers / subprocessors that help us run the Service (hosting, payments, email delivery,
video, AI) — see the full list on our Subprocessors page. They are bound to protect the data and may act only on our instructions.
- At your direction, with third parties you connect (e.g., your payment processor). Payments are
processed by Stripe; ClimbSuite never receives or stores your customers' full card numbers — Stripe collects and secures that data directly.
- Legal / safety: to comply with law, enforce our terms, or protect rights and safety.
- Business transfers: in a merger, acquisition, or asset sale, with notice as required.
- We do not sell personal information, and we do not "share" it for cross-context behavioral
advertising as those terms are defined under the CPRA.
6. Your rights and privacy choices
Depending on your location (e.g., GDPR/EEA, UK, CPRA/California), you may have rights to know/access, correct, delete, port, or restrict your personal data, and to opt out of certain processing or withdraw consent. If you have a ClimbSuite account, you can exercise the most common rights yourself, any time, from Settings → Privacy & your data: download a machine-readable export of your data, or permanently delete your account and data. For any other privacy request, or if you are a contact of one of our customers, contact tero@sisulogistic.co — if you are a customer's contact, we will direct your request to that customer (the controller) and assist them as processor. We do not charge a fee or discriminate against you for exercising these rights.
7. International transfers
We may process data in the United States and other countries. Where required, we use appropriate safeguards (e.g., Standard Contractual Clauses) for cross-border transfers.
8. Data retention
We keep personal data as long as needed to provide the Service and for legitimate/legal purposes (for example, billing records for tax/audit purposes, or the minimum records needed to resolve a dispute), then delete or anonymize it. Requesting deletion via Settings → Privacy & your data erases your account data immediately, other than anything we are legally required to retain, which is disclosed to you at the time of the request.
9. Security
We use reasonable technical and organizational measures (access controls, encryption in transit, tenant isolation) to protect data. No system is perfectly secure.
10. Children and managed minor profiles
The Service is not directed to children, and individuals do not create their own ClimbSuite accounts as minors. However, some of our customers (for example, dance studios, youth sports programs, flight schools, and other education-focused organizations) use the Service's roster tools to create and manage minor profiles on behalf of a parent or legal guardian — including a guardian's contact information and a record of the guardian's consent. In these cases, our customer (the tenant organization) is the data controller responsible for obtaining verifiable parental or guardian consent before submitting a minor's data to the Service, and for managing that consent going forward; ClimbSuite acts only as a processor under the Data Processing Addendum and does not independently collect data from minors.
11. Governing law
This Policy is governed by the laws of the State of Florida, USA, without regard to conflict-of-laws rules. Any dispute arising out of or relating to this Policy will be brought exclusively in the state and federal courts located in the State of Florida, and you consent to personal jurisdiction and venue there.
12. Changes
We may update this Policy and will post the new version with a revised date; material changes will be notified as required.
13. Contact
Sisu Logistic, LLC (DBA Sisu IO), 25050 SW 114th Ave, Princeton, FL 33032 — tero@sisulogistic.co. For data access, export, correction, or deletion requests, use Settings → Privacy & your data if you have an account, or email tero@sisulogistic.co.