This notice describes how BridgeLync handles information in the BridgeLync Assessments platform. It supplements — and is controlled by — your organization's signed service agreement with BridgeLync.
Account information. Your name, work email address, role, and organization. Passwords are stored only as salted hashes; multi-factor authentication secrets are stored encrypted.
Content your organization provides. Documents you upload, assessment and survey responses, KPI and reporting data, comments, and messages you send in analysis chat.
Usage and security records. An audit log of significant actions (sign-ins, exports, approvals, terms acceptance) including timestamps and IP addresses, kept for security and accountability.
To operate the service: authentication and access control, storing and processing the content your organization submits, running the AI-assisted analysis you request, sending transactional email (invitations, notifications, password resets), providing support, and maintaining security. We do not sell personal information, and we do not use it for advertising.
AI features (document analysis, report generation, analysis chat, assessment drafting) process the content you submit using Anthropic Claude models via Amazon Bedrock. Your content is used only to produce the outputs you request. It is not used to train AI models.
The platform runs on Amazon Web Services in the United States. AWS services acting as subprocessors include S3 (file storage), RDS (database), Bedrock (AI processing), SES (email delivery), and Lambda (background processing). Data is encrypted in transit (TLS) and at rest on AWS infrastructure.
Your organization's content is not shared with other customer organizations. BridgeLync personnel access it only to operate and support the service. We disclose information outside BridgeLync only as directed by your organization's agreement or as required by law.
Account and organizational content is retained for the life of your organization's agreement and handled per that agreement at offboarding. Audit-log entries are pruned on a rolling schedule.
The platform is not a HIPAA Business Associate environment and must not be used to store Protected Health Information — see the customer terms presented at first sign-in.
Questions about this notice: contact your organization's administrator or BridgeLync at privacy@bridgelync.com.