EP
E&P Directory
epdirectory.com

Privacy Policy

Effective Date: March 29, 2026  ·  Last Updated: March 29, 2026  ·  Governing Entity: Vizion Investments LLC

⚠️ Attorney Review Recommended. This document is a comprehensive draft. It should be reviewed by a licensed attorney before relying on it as a binding legal document. State privacy laws change frequently — verify current requirements before deployment.

Table of Contents

  1. Overview and Scope
  2. Information We Collect
  3. How We Use Your Information
  4. How We Share Your Information
  5. AI Features and Data Processing
  6. Cookies and Tracking Technologies
  7. Data Retention
  8. Security
  9. Children's Privacy
  10. Your Rights and Choices
  11. California Residents — CCPA/CPRA
  12. Virginia Residents — VCDPA
  13. Colorado Residents — CPA
  14. Connecticut Residents — CTDPA
  15. Texas Residents — TDPSA
  16. Other State Residents
  17. Data Transfers
  18. Changes to This Policy
  19. Contact Us

1. Overview and Scope

This Privacy Policy describes how Vizion Investments LLC ("Company", "we", "us", "our"), operator of E&P Directory at epdirectory.com, collects, uses, discloses, and protects information about users of our Platform.

This Policy applies to all users of the Platform, including Engineers, Procurement Professionals, Suppliers, and visitors to epdirectory.com. It covers information collected through the Platform, our emails, and any related services.

This Platform is designed for business-to-business (B2B) commercial use. Information you provide is primarily business or professional in nature. Where personal data is incidentally collected, we handle it in accordance with this Policy.

2. Information We Collect

2.1 Information You Provide Directly

CategoryExamplesWho Provides It
Account InformationName, email address, company name, phone number, role (engineer/supplier)All users at registration
Professional ProfileCompany specialties, certifications, capabilities, years in businessSuppliers
RFQ ContentProject descriptions, technical specifications, budget ranges, timelinesEngineers
Quote DataPricing, delivery terms, warranty terms, conditionsSuppliers
CommunicationsMessages sent through the Platform, support emailsAll users
Payment InformationBilling address, last 4 digits of card (full card data held by Stripe)Paying subscribers
Ratings and ReviewsStar ratings, written comments about suppliersEngineers
Job PostingsJob titles, descriptions, salary ranges, application emailSuppliers
Jim Chat ConversationsQuestions and messages submitted to the AI assistantAll users
Advertising InquiriesCompany name, contact person, advertising interestProspective advertisers

2.2 Information Collected Automatically

2.3 Information from Third Parties

3. How We Use Your Information

PurposeLegal Basis (where applicable)
Provide, operate, and maintain the Platform and its featuresContract performance
Process payments and manage subscriptionsContract performance
Match Engineers with relevant Suppliers via AI scoringContract performance / Legitimate interest
Power Jim AI assistant responses using platform contextContract performance / Consent
Generate aggregated price intelligence and market analyticsLegitimate interest
Send transactional emails (account, billing, RFQ notifications)Contract performance
Send marketing and promotional communications (with opt-out)Legitimate interest / Consent
Detect and prevent fraud, abuse, and security incidentsLegitimate interest / Legal obligation
Comply with legal obligations and respond to lawful requestsLegal obligation
Improve our AI algorithms and platform featuresLegitimate interest
Analyse Platform usage and performanceLegitimate interest

We do not sell your personal information to third parties for their own marketing purposes.

4. How We Share Your Information

4.1 With Other Platform Users (By Design)

The Platform is designed to facilitate connections between Engineers and Suppliers. The following information is visible to other users as part of the Platform's core function:

4.2 Service Providers

We share information with trusted service providers who process it on our behalf:

ProviderPurposeData Shared
Stripe, Inc.Payment processingBilling information, subscription events
Anthropic, PBCJim AI assistant (LLM processing)Chat messages, platform context (anonymised)
Render Services, Inc.Cloud hosting and infrastructureAll Platform data (infrastructure level)
ResendTransactional email deliveryEmail address, email content
TelegramInternal operational notificationsAdvertising inquiry data, operational alerts

4.3 Legal Requirements

We may disclose your information if required by law, regulation, legal process, or governmental request, or if we believe disclosure is necessary to protect the rights, property, or safety of the Company, our users, or others.

4.4 Business Transfers

If we are involved in a merger, acquisition, asset sale, or similar transaction, your information may be transferred as part of that transaction. We will notify you before your information becomes subject to a materially different privacy policy.

4.5 With Your Consent

We may share your information in other ways with your explicit consent.

5. AI Features and Data Processing

5.1 Jim AI Assistant

When you use Jim, your messages and relevant platform context (your role, active RFQs, platform statistics) are transmitted to Anthropic, PBC for processing via their API. We do not transmit your full name, payment information, or contact details to Anthropic.

Anthropic processes this data in accordance with their API data usage policies. As of the date of this Policy, Anthropic does not use API inputs to train their models by default. You should review Anthropic's current privacy policy for the most up-to-date information.

Jim conversation history is stored on our servers to provide conversation continuity within a session. We may review conversation logs for safety monitoring, abuse prevention, and service improvement.

5.2 AI Scoring Data

The 40-point supplier scoring algorithm processes RFQ requirements and supplier data to generate match scores. This processing occurs within our infrastructure and no data is sent to third parties for scoring purposes.

6. Cookies and Tracking Technologies

Cookie TypePurposeDurationCan be disabled?
Session / AuthenticationKeep you logged in, maintain session stateSession / 30 daysNo (required for Platform to function)
PreferenceRemember your settings and preferences1 yearYes (functionality may be affected)
AnalyticsUnderstand how users interact with the Platform (aggregated)Up to 2 yearsYes

We do not use third-party advertising cookies or sell cookie data to advertisers. You can manage cookies through your browser settings. Note that disabling essential cookies will prevent you from using the Platform.

7. Data Retention

Data CategoryRetention PeriodReason
Account dataDuration of account + 3 years after closureLegal compliance, dispute resolution
RFQ and quote data5 years from transaction dateBusiness records, dispute resolution
Payment records7 yearsTax and accounting legal requirements
Jim chat logs90 days rollingSafety monitoring, service improvement
Ratings and reviewsDuration of supplier's active account + 2 yearsPlatform integrity
Server access logs90 daysSecurity monitoring
Marketing communicationsUntil opt-out + 30 days processingCAN-SPAM / marketing compliance

We may retain certain data longer where required by applicable law or where necessary for legitimate business purposes such as litigation holds.

8. Security

We implement reasonable technical and organisational security measures to protect your information, including:

No method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security. In the event of a data breach affecting your rights, we will notify you as required by applicable state breach notification laws (see Section 16).

9. Children's Privacy

The Platform is not directed to, and we do not knowingly collect personal information from, individuals under the age of 18. If we become aware that we have collected personal information from a person under 18, we will delete that information promptly. If you believe we may have information from or about a minor, contact us at ads@epdirectory.com.

10. Your Rights and Choices

AccessRequest a copy of the personal data we hold about you
CorrectionRequest correction of inaccurate or incomplete data
DeletionRequest deletion of your data (subject to legal retention requirements)
PortabilityRequest your data in a machine-readable format
Opt-Out (Marketing)Unsubscribe from marketing emails at any time via the link in any email
ObjectObject to processing based on legitimate interests

To exercise any of these rights, contact us at ads@epdirectory.com. We will respond within 30 days (or within the timeframe required by applicable state law). We will not discriminate against you for exercising your privacy rights.

Note: Some requests may be limited where retention is required by law, where the data is necessary to complete a transaction you requested, or where deletion would adversely affect another user's rights.

11. California Residents — CCPA / CPRA

California Consumer Privacy Act (CCPA) as amended by CPRA

If you are a California resident, you have the following rights under the CCPA/CPRA:

Categories of personal information collected: Identifiers, commercial information, professional/employment information, internet/network activity, inferences drawn from the above.

Categories of sources: Directly from you, automatically from your use of the Platform, from payment processors.

Business or commercial purposes for collection: Providing the Platform, processing transactions, improving services, security, legal compliance.

Categories of third parties with whom we share: Service providers (Stripe, Anthropic, Render, Resend) under data processing agreements.

Do Not Sell or Share: We do not sell personal information. We do not share personal information for cross-context behavioural advertising.

To submit a CCPA request: email ads@epdirectory.com with subject line "CCPA Request". We will verify your identity before processing. You may designate an authorised agent to make a request on your behalf.

California residents may also contact the California Privacy Protection Agency (CPPA) at cppa.ca.gov.

12. Virginia Residents — VCDPA

Virginia Consumer Data Protection Act

Virginia residents have the right to: access, correct, delete, and obtain a copy of personal data; opt out of processing for targeted advertising, sale, or profiling for decisions with legal or similarly significant effects.

We do not process personal data for targeted advertising, sell personal data, or use personal data for profiling in furtherance of decisions with legal or similarly significant effects on consumers.

To exercise your rights, email ads@epdirectory.com. We will respond within 45 days, extendable by an additional 45 days with notice. If we decline to take action on a request, you may appeal by replying to our response. If the appeal is denied, you may contact the Virginia Attorney General at oag.state.va.us.

13. Colorado Residents — CPA

Colorado Privacy Act

Colorado residents have the right to: access, correct, delete, and obtain a portable copy of personal data; opt out of processing for targeted advertising, sale of personal data, and profiling.

Universal Opt-Out: We honour the Global Privacy Control (GPC) signal as an opt-out from the sale of personal data and targeted advertising where technically feasible.

We do not sell personal data or use it for targeted advertising or profiling with significant effects. To exercise other rights, email ads@epdirectory.com. Response time: 45 days (extendable by 45 days). Appeals may be submitted to the Colorado Attorney General at coag.gov.

14. Connecticut Residents — CTDPA

Connecticut Data Privacy Act

Connecticut residents have the right to: access, correct, delete, and obtain a portable copy of personal data; opt out of targeted advertising, sale of personal data, and profiling for decisions with significant effects.

We do not sell personal data or process it for targeted advertising or consequential profiling. To exercise your rights, email ads@epdirectory.com. Appeals may be submitted to the Connecticut Attorney General.

15. Texas Residents — TDPSA

Texas Data Privacy and Security Act (effective July 1, 2024)

Texas residents have the right to: access, correct, delete, and obtain a portable copy of personal data; opt out of processing for targeted advertising, sale of personal data, or profiling for consequential decisions.

We do not sell personal data, process it for targeted advertising, or use it for consequential profiling. To exercise your rights, email ads@epdirectory.com. We will respond within 45 days. Appeals may be submitted to the Texas Attorney General.

16. Other State Residents

The following states have enacted or are in the process of enacting comprehensive privacy laws. We are committed to compliance with all applicable state privacy legislation:

StateLawKey Right / Note
MontanaMontana Consumer Data Privacy Act (MCDPA, eff. Oct 2024)Access, correct, delete, portability, opt-out of sale/targeted advertising
OregonOregon Consumer Privacy Act (OCPA, eff. Jul 2024)Broad rights; covers non-profit data in some cases
IndianaIndiana Consumer Data Protection Act (ICDPA, eff. Jan 2026)Access, correct, delete, portability, opt-out
IowaIowa Consumer Data Protection Act (ICDPA, eff. Jan 2025)Access, delete, portability, opt-out of sale/targeted advertising
TennesseeTennessee Information Protection Act (TIPA, eff. Jul 2025)Access, correct, delete, portability, opt-out
MinnesotaMinnesota Consumer Data Privacy Act (MCDPA, eff. Jul 2025)Access, correct, delete, portability, opt-out; includes right to question profiling
MarylandMaryland Online Data Privacy Act (MODPA, eff. Oct 2025)Among the strictest: limits data minimisation requirements
NebraskaNebraska Data Privacy Act (NDPA, eff. Jan 2025)Access, correct, delete, portability, opt-out
New HampshireNew Hampshire Privacy Act (NHPA, eff. Jan 2025)Access, correct, delete, portability, opt-out
New JerseyNew Jersey Data Privacy Act (NJDPA, eff. Jan 2025)Access, correct, delete, portability, opt-out; honours universal opt-out
DelawareDelaware Personal Data Privacy Act (DPDPA, eff. Jan 2025)Access, correct, delete, portability, opt-out; applies to ages 13–17 data too
KentuckyKentucky Consumer Data Protection Act (KCDPA, eff. Jan 2026)Access, correct, delete, portability, opt-out
All 50 StatesState Breach Notification LawsWe will notify affected residents of qualifying data breaches within the timeframe required by each state's law (typically 30–90 days). Most states require notification where the breach compromises unencrypted personal information.

Regardless of your state of residence, you may contact us at ads@epdirectory.com to exercise privacy rights. We will apply rights consistent with applicable law for your state.

17. Data Transfers

The Platform is operated from the United States. If you access the Platform from outside the United States, please be aware that your information may be transferred to and processed in the United States, where data protection laws may differ from those in your country.

We do not specifically target users outside the United States. The Platform is designed for US-based B2B commercial use. If you are located in the European Economic Area (EEA), United Kingdom, or other jurisdictions with transfer restrictions, please be aware that by using the Platform you acknowledge this data transfer.

18. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated Policy on the Platform with a revised "Last Updated" date and, for registered users, by sending an email notification at least 14 days before the changes take effect.

State privacy laws change frequently. We review this Policy at least annually and update it to reflect new legal requirements. We recommend reviewing this Policy periodically.

19. Contact Us

For privacy questions, requests, or complaints:

Privacy Contact — E&P Directory
Operated by Vizion Investments LLC
Email: ads@epdirectory.com
Subject line: "Privacy Request" or "Privacy Question"
Website: www.epdirectory.com

We aim to respond to all privacy requests within 30 days.